CVE-2026-3833Gnu · Gnutls
Vulnerability data via NVD (ingested)
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-3833product:"Gnu Gnutls"http.html:"Gnutls"More intel sources (5)
vuln:CVE-2026-3833vulnerabilities.cve_id: CVE-2026-3833CVE-2026-3833CVE-2026-3833"CVE-2026-3833" exploit -site:nvd.nist.gov