CVE-2026-33846Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-05-04); latest day: 1
  • 7 total mentions across 6 days

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-12: 1Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Mentions · 2026-06-09: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-09: 1Technical Details · 2026-07-02: 105-0405-1205-2405-2706-0907-02
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-121
Patch1
2026-05-241
Patch1
2026-05-271
General1
2026-06-091
Disclosure1
2026-07-021
Disclosure1
Full discourse7 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    صدرت اليوم ٨ ثغرات بتصنيف حرج او عالي الخطورة في مكتبة GnuTLS الي شرحتها في التغريده المقتبسه ـ📍 (CVE-2026-42010) تقييم (NVD): 🔴 9.8 (حرجة) تقييم (Red Hat): 🟠 7.1 (عالية) ـ📍 (CVE-2026-33845) تقييم (NVD): 🔴 9.1 (حرجة) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42013) تقييم (Red Hat): 🟠 8.2 (عالية) تصنيف (GnuTLS) الرسمي: 🟡 (متوسطة) ـ📍 (CVE-2026-5260) تقييم (Red Hat): 🟠 8.2 (عالية) ـ📍 (CVE-2026-33846) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42009) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-3833) تقييم (NVD): 🟠 7.4 (عالية) تقييم (Red Hat): 🟡 6.5 (متوسطة) ـ📍 (CVE-2026-42011) تقييم (Red Hat / Ubuntu CVSS): 🟠 7.4 (عالية) أولوية (Ubuntu) الفعلية: 🟡 (متوسطة)

    Post summary

    The post announces eight new GnuTLS CVEs and their severity scores, but offers no proof of concept, exploit, or patch information.

    03023124.3K
    50.0K followersView on X
  • Haruto Kimura@harutosec
    Disclosure

    The bug classes don't care how new the primitive is — fresh parsing and length-handling code in C reintroduces them every time. From my audits this year: wolfSSL ECH config parser (stack overflow, CVE-2026-3849), GnuTLS DTLS fragment reassembly (heap overflow, CVE-2026-33846), Mbed TLS FFDH export (heap overflow, CVE-2026-34875). PQ rollout means a lot of fresh C. The prediction sounds right.

    Post summary

    The post reports the discovery of three CVEs in TLS libraries, providing brief technical details about the overflow weaknesses, but offers no Proof of Concept, exploit code, patch information, or evidence of active exploitation.

    00011161
    20 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-33846: high severity (CVSS 7.5). Scope affected systems for a remote code execution issue. Treat it like a small fire drill before it becomes a large one.

    Post summary

    The brief notice highlights a high‑severity (CVSS 7.5) remote code execution vulnerability (CVE‑2026‑33846) with no PoC, patch, or exploitation evidence.

    1000047
    315 followersView on X
  • iototsecnews@iototsecnews
    Patch

    GnuTLS 3.8.13 リリース:認証バイパスとメモリ破損を含む複数の脆弱性を修正 https://iototsecnews.jp/2026/05/05/gnutls-3-8-13-released-with-fix-for-12-vulnerabilities-affecting-network-communications/ 今回のアップデートでは、メモリ管理の不備や認証処理のロジックミスを原因とする脆弱性が修正されています。具体的には、メモリの境界チェックが不足していたために発生する、CVE-2026-33846 や CVE-2026-33845 などのヒープ関連の脆弱性が修正されています。また、ユーザー名処理の不備からログインを許してしまう CVE-2026-42010 などの、プログラムが想定外の入力に対して正しく振る舞えない問題も対処されています。特に、DTLS の実装や証明書検証 (CVE-2026-42013) といった通信の根幹に関わる部分で、境界値の確認やポインタの扱い、名前の照合ルールが不十分であったことが、深刻なリスクを生むきっかけとなっています。ご利用のチームは、ご注意ください。 #CVE202633845 #CVE202633846 #CVE20263833 #CVE202642009 #CVE202642010 #CVE202642013 #CVE202642014 #CVE20265419 #GnuTLS #Vulnerability

    Post summary

    The article announces the GnuTLS 3.8.13 release, which patches 12 CVEs including memory‑boundary and authentication bypass flaws.

    01000113
    491 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming han… https://www.cve.org/CVERecord?id=CVE-2026-33846

    Post summary

    The post announces a newly disclosed heap buffer overflow in GnuTLS’s DTLS handshake logic, providing basic technical details but no exploit, patch, or active use information.

    00010198
    57.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-33846 - GnuTLS DTLS heap buffer overflow (CVSS 7.5). Remotely exploitable without auth. Affects DTLS handshake fragment reassembly. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/YgpzyQyB3V

    Post summary

    The tweet announces a high‑severity buffer overflow in GnuTLS, urges immediate patching, but provides no exploit tools or evidence of active attacks.

    0000058
    30 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33846 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming han… https://www.cve.org/CVERecord?id=CVE-2026-33846 ----- Traducción: CVE-2026-33846 Exi… http://infoflow.cloud`

    Post summary

    A heap buffer overflow vulnerability has been disclosed in GnuTLS’s DTLS handshake fragment reassembly logic (merge_handshake_packet()). No PoC, exploit, or patch is mentioned.

    0000036
    75 followersView on X

Explore more