CVE-2026-3833Disclosure(gnu / enterprise_linux)

MEDIUMCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch gnu enterprise_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • gnutls
  • hardened_images
  • openshift_container_platform

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
enterprise_linuxgnutlshardened_imagesopenshift_container_platform

7 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-30: 1Mentions · 2026-05-27: 1Mentions · 2026-06-29: 1Active Exploitation · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-29: 104-3005-2706-29
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-301
Disclosure1
2026-05-271
Disclosure1
2026-06-291
Active Exploitation1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    صدرت اليوم ٨ ثغرات بتصنيف حرج او عالي الخطورة في مكتبة GnuTLS الي شرحتها في التغريده المقتبسه ـ📍 (CVE-2026-42010) تقييم (NVD): 🔴 9.8 (حرجة) تقييم (Red Hat): 🟠 7.1 (عالية) ـ📍 (CVE-2026-33845) تقييم (NVD): 🔴 9.1 (حرجة) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42013) تقييم (Red Hat): 🟠 8.2 (عالية) تصنيف (GnuTLS) الرسمي: 🟡 (متوسطة) ـ📍 (CVE-2026-5260) تقييم (Red Hat): 🟠 8.2 (عالية) ـ📍 (CVE-2026-33846) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-42009) تقييم (Red Hat): 🟠 7.5 (عالية) ـ📍 (CVE-2026-3833) تقييم (NVD): 🟠 7.4 (عالية) تقييم (Red Hat): 🟡 6.5 (متوسطة) ـ📍 (CVE-2026-42011) تقييم (Red Hat / Ubuntu CVSS): 🟠 7.4 (عالية) أولوية (Ubuntu) الفعلية: 🟡 (متوسطة)

    Post summary

    The text announces eight new high or critical vulnerabilities in GnuTLS, providing CVE numbers and severity scores from NVD and Red Hat, without referencing any PoC, exploit, active use, or patch information.

    03023124.3K
    50.0K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Cisco CUCM (CVE-2026-20230) actively exploited for root access, jeopardizing real-time comms. New GnuTLS flaws (CVE-2026-3833, etc.) impact TLS/DTLS integrity. Patch immediately! #Cybersecurity #Vulnerabilities #RealTimeComms

    Post summary

    Cisco CUCM’s CVE‑2026‑20230 is actively exploited for root access, and new GnuTLS CVEs (e.g., CVE‑2026‑3833) threaten TLS/DTLS integrity; immediate patching is urged.

    0000072
    14 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) o… https://www.cve.org/CVERecord?id=CVE-2026-3833

    Post summary

    A vulnerability in gnutls involving case-sensitve nameConstraints comparisons on dNSName is disclosed, with technical details provided but no PoC, exploit, patch, or active exploitation evidence.

    00000107
    57.3K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appgnugnutls---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatopenshift_container_platform4.0--

Explore more