LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33308

mod gnutls project · mod gnutls

Published
CVSS6.8
Severitymedium
WeaknessCWE-295
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension. An attacker with access to the private key for a valid certificate issued by a CA trusted for TLS client authentication but designated for a different purpose could have used that certificate to improperly access resources requiring TLS client authentication. Server configurations that do not use client certificates (`GnuTLSClientVerify ignore`, the default) are not affected. The problem has been fixed in version 0.13.0 by rewriting certificate verification to use `gnutls_certificate_verify_pee

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33308

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33308.