Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3373 articles · 142302 vulns · 36/41 feeds (7d)
← Back to list
3.7
CVE-2026-3832PATCHED
red hat · red hat enterprise linux

Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response

Description

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.

Affected Products

VendorProductVersions
red hatred hat enterprise linux0

References

  • https://access.redhat.com/errata/RHSA-2026:13274(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-3832(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2445762(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.com/gnutls/gnutls/-/issues/1801

Related News (3 articles)

Tier A
Microsoft MSRC4d ago
CVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-3832 | GnuTLS Certificate Status Protocol early validation
→ No new info (linked only)
Tier B
BSI Advisories11d ago
[NEU] [hoch] GnuTLS: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.13.7 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.8.13-1.hum1
CWECWE-179
PublishedApr 30, 2026
Last enriched11d agov2
Trending Score25
Source articles3
Independent3
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4424
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
Trending: 38
NONECVE-2026-33845
Gnutls: gnutls: denial of service via dtls zero-length fragment
Trending: 26
HIGHCVE-2026-4802
Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui
Trending: 26
PRE-CVE
Multiple vulnerabilities in Red Hat Linux kernel
Trending: 20
NONECVE-2026-42010
Gnutls: gnutls: authentication bypass via nul character in username
Trending: 18

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 30, 2026
Discovered by ZDM
Apr 30, 2026
Updated: description, severity
Apr 30, 2026
Patch Available
May 4, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated description with new details, changed vendor to GnuTLS, product to Certificate Status Protocol, and severity to HIGH.

descriptionseverity
via VulDB
v111d ago

Initial creation