CVE-2026-33307 Details
Description
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t x509[]` array without checking the number of certificates is less than or equal to the array size. `gnutls_x509_crt_t` is a `typedef` for a pointer to an opaque GnuTLS structure created using with `gnutls_x509_crt_init()` before importing certificate data into it, so no attacker-controlled data was written into the stack buffer, but writing a pointer after the last array element generally triggered a segfault, and could theoretically cause stack corruption otherwise (not observed in practice). Server configurations that do not use client certificates (`GnuTLSClientVerify ignore`, the default) are not affected. The problem has been fixed in version 0.12.3 by checking the length of the provided certificate chain and rejecting it if it exceeds the buffer length, and in version 0.13.0 by rewriting certificate verification to use `gnutls_certificate_verify_peers()`, removing the need for the buffer entirely. There is no workaround. Version 0.12.3 provides the minimal fix for users of 0.12.x who do not wish to upgrade to 0.13.0 yet.
A stack-based buffer overflow vulnerability has been identified in the Apache mod_gnutls module, which is based on GnuTLS. This issue affects versions prior to 0.12.3 and 0.13.0. The vulnerability arises because the client certificate verification process imports the certificate chain from the client into a fixed-size array of GnuTLS certificate structures. This import occurs without verifying that the number of certificates does not exceed the array's capacity. While this flaw does not allow for the writing of attacker-controlled data into the stack buffer, it can lead to a segmentation fault by overwriting a pointer beyond the last array element. Theoretically, this could cause stack corruption, although such an effect has not been observed in practice. Server configurations that do not require client certificates are not vulnerable.
Users can upgrade to mod_gnutls version 0.12.3 or 0.13.0 to address this vulnerability. Version 0.12.3 includes a critical fix for users on the 0.12.x branch who prefer not to upgrade to 0.13.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mod gnutls project mod gnutls | < 0.12.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |