CVE-2025-14831Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-10); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-09: 2Mentions · 2026-02-10: 3Mentions · 2026-02-18: 1Mentions · 2026-04-08: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 3Technical Details · 2026-02-18: 1Technical Details · 2026-04-08: 102-0902-1002-1804-08
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure2
2026-02-103
Disclosure2Patch1
2026-02-181
Patch1
2026-04-081
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Patch

    GnuTLS 3.8.12 fixes 2 CVEs https://www.openwall.com/lists/oss-security/2026/02/09/6 CVE-2026-1584: NULL pointer dereference in PSK binder verification (TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to DoS) CVE-2025-14831: Name constraint processing performance issue

    Post summary

    GnuTLS 3.8.12 includes patches for CVE-2026-1584 (NULL pointer dereference causing DoS) and CVE-2025-14831 (performance issue), with no active exploitation or PoC reported.

    12051786
    4.4K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @oss_security CVE-2025-14831: Name Constraint Processing Performance Issue. It is related to the handling of X.509 certificate name constraints and causes performance degradation during certificate validation. ⏳ #CVE

    Post summary

    The post announces CVE‑2025‑14831, a performance degradation issue in X.509 name‑constraint processing during certificate validation.

    1000048
    315 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14831 Denial of Service Vulnerability in GnuTLS via Malicious C... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14831 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces the discovery of a Denial of Service vulnerability (CVE-2025-14831) in GnuTLS, linking to a vulnerability details page but providing no PoC, exploit, patch, or active exploitation information.

    0000156
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE Linux Micro 6.2 releases gnutls update patching CVE-2025-14831 DoS and CVE-2025-9820 buffer overflow, admins urged to apply via YaST or zypper immediately. https://threatcluster.io/cluster/suse-linux-micro-62-gnutls-vulnerabilities-addressed-in-late-97d26735

    Post summary

    The post announces a patch for SUSE Linux Micro 6.2 that addresses CVE‑2025‑14831 (DoS) and CVE‑2025‑9820 (buffer overflow), urging admins to apply it urgently.

    00000372
    133 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Debian community! 🐧 A significant DoS vulnerability (CVE-2025-14831) in the #GnuTLS library has been patched. Read more: 👉 https://tinyurl.com/57nj5krz #Security https://t.co/s0NgAZrKGy

    Post summary

    The tweet announces that CVE‑2025‑14831, a DoS vulnerability in GnuTLS, has been patched, with a link to additional information.

    0000050
    1.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    GNUTLS-SA-2026-02-09-1、CVE-2026-1584 Severity High; invalid pointer access GNUTLS-SA-2026-02-09-2、CVE-2025-14831 Severity Medium; denial of service The GnuTLS Transport Layer Security Library https://www.gnutls.org/security-new.html

    Post summary

    The entry announces two GnuTLS vulnerabilities, CVE‑2026‑1584 (high severity, invalid pointer access) and CVE‑2025‑14831 (medium severity, denial of service), without mentioning exploitation, patches, or PoC.

    00000512
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14831 A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafte… https://www.cve.org/CVERecord?id=CVE-2025-14831

    Post summary

    CVE-2025-14831 is a newly disclosed denial‑of‑service vulnerability in GnuTLS that allows attackers to exhaust CPU and memory resources through crafted traffic.

    00000282
    56.5K followersView on X

Explore more