CVE-2026-33307Disclosure(mod_gnutls_project / mod_gnutls)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t x509[]` array without checking the number of certificates is less than or equal to the array size. `gnutls_x509_crt_t` is a `typedef` for a pointer to an opaque GnuTLS structure created using with `gnutls_x509_crt_init()` before importing certificate data into it, so no attacker-controlled data was written into the stack buffer, but writing a pointer after the last array element generally triggered a segfault, and could theoretically cause stack corruption otherwise (not observed in practice). Server configurations that do not use client certificates (`GnuTLSClientVerify ignore`, the default) are not affected. The problem has been fixed in version 0.12.3 by checking the length of the provided certificate chain and rejecting it if it exceeds the buffer length, and in version 0.13.0 by rewriting certificate verification to use `gnutls_certificate_verify_peers()`, removing the need for the buffer entirely. There is no workaround. Version 0.12.3 provides the minimal fix for users of 0.12.x who do not wish to upgrade to 0.13.0 yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mod_gnutls

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
mod_gnutls

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 103-2403-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure2
2026-03-251
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33307 Buffer Overflow Vulnerability in Mod_gnutls Apache HTTPD TLS Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33307

    Post summary

    The post announces the discovery of CVE‑2026‑33307, a buffer‑overflow flaw in Apache HTTPD's mod_gnutls module, but provides no PoC, exploit, or patch information.

    0001156
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33307 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33307 #CVE-2026-33307 #CVE #High #Apache #CyberSecurity #InfoSec https://t.co/FXgc6I5Udz

    Post summary

    The post announces a new CVE with basic technical details and severity information, focusing on the disclosure of the vulnerability.

    0000036
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33307 Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate… https://www.cve.org/CVERecord?id=CVE-2026-33307

    Post summary

    The text discloses CVE-2026-33307 as a client certificate verification flaw in mod_gnutls before version 0.12.3 and 0.13.0, without providing PoC, exploit, or patch details.

    00000113
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmod_gnutls_projectmod_gnutls---

Explore more