CVE-2026-3832 Details
Description
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.
A vulnerability in GnuTLS's handling of Online Certificate Status Protocol (OCSP) responses can lead to a security bypass during TLS handshakes. This issue arises from a logic error in processing multi-record OCSP responses. A remote attacker could exploit this flaw by presenting a crafted OCSP response, causing a client with OCSP verification enabled to incorrectly accept a revoked server certificate. As a result, this could compromise the trust relationship between the client and server.
Users can upgrade to GnuTLS version 3.8.13, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.com/gnutls/gnutls/-/issues/1801 | CISA-ADP | ExploitIssue TrackingVendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:13274 | [email protected] | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:20612 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:20613 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:26319 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:26409 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:29197 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:58981 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2026-3832 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2445762 | [email protected] | Issue TrackingThird Party Advisory |
| https://gitlab.com/gnutls/gnutls/-/issues/1801 | [email protected] | ExploitIssue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-179 | Incorrect Behavior Order: Early Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu gnutls | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CISA-ADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 3, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | New CVE Received | [email protected] |