CVE-2026-33308Disclosure(mod_gnutls_project / mod_gnutls)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension. An attacker with access to the private key for a valid certificate issued by a CA trusted for TLS client authentication but designated for a different purpose could have used that certificate to improperly access resources requiring TLS client authentication. Server configurations that do not use client certificates (`GnuTLSClientVerify ignore`, the default) are not affected. The problem has been fixed in version 0.13.0 by rewriting certificate verification to use `gnutls_certificate_verify_peers()`, and requiring key purpose id-kp-clientAuth (also known as `tls_www_client` in GnuTLS) by default if the Extended Key Usage extension is present. The new `GnuTLSClientKeyPurpose` option allows overriding the expected key purpose if needed (please see the manual for details). Behavior for certificates without an Extended Key Usage extension is unchanged. If dedicated (sub-)CAs are used for issuing TLS client certificates only (not for any other purposes) the issue has no practical impact.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mod_gnutls

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
mod_gnutls

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-24: 103-2403-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-241
Disclosure1
2026-03-251
General1
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33308 📊 Severity: 6.8 🚨 Risk Level: Medium 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33308 #CVE-2026-33308 #CVE #Medium #Apache #CyberSecurity #InfoSec https://t.co/0iLcx3AQOB

    Post summary

    The tweet announces CVE‑2026‑33308, noting its medium severity for Apache and linking to the NVD entry, without additional technical or exploitation details.

    0000028
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33308 Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in… https://www.cve.org/CVERecord?id=CVE-2026-33308

    Post summary

    The post briefly announces CVE-2026-33308, describing a certificate validation flaw in mod_gnutls and pointing to the CVE record; it provides no proof of concept, exploit, or patch details.

    00000116
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmod_gnutls_projectmod_gnutls---

Explore more