CVE-2026-3833

Executive Summary

A flaw in GnuTLS allows a remote attacker to bypass certificate policy checks by exploiting case-sensitive comparisons of nameConstraints labels (dNSName or rfc822Name) in excludedSubtrees or permittedSubtrees. By crafting a leaf certificate with differing case in the SAN, a certificate that should be rejected can be accepted, enabling unauthorized access or information disclosure.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2026-04-30T18:16:30.577 - Last Modified: 2026-09-28T02:17:25.153

Original Description: A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of nameConstraints labels, specifically for dNSName (DNS) or rfc822Name (email) constraints within excludedSubtrees or permittedSubtrees. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.

"Our kindness may be the most persuasive argument for that which we believe."

— Gordon Hinckley
Source: NVD