CVE-2026-3833 Details
Description
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
A vulnerability in GnuTLS has been identified, where the library performs case-sensitive comparisons of nameConstraints labels in X.509 certificates. This issue specifically affects dNSName (DNS) and rfc822Name (email) constraints within excludedSubtrees or permittedSubtrees. A remote attacker can exploit this flaw by crafting a leaf certificate with intentional casing differences in the Subject Alternative Name (SAN). As a result, a certificate that should be rejected is accepted, leading to a policy bypass. This vulnerability could enable unauthorized access or information disclosure, particularly in environments that rely on nameConstraints to enforce domain boundaries in delegated Public Key Infrastructure (PKI) hierarchies.
Users can upgrade to GnuTLS version 3.8.13, which addresses this vulnerability by implementing case-insensitive string comparisons for nameConstraints, ensuring proper enforcement of exclusion rules.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-178 | Improper Handling of Case Sensitivity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu gnutls | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
30 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 14, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | CISA-ADP |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 26, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | CVE Modified | [email protected] |
| May 27, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 3, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | New CVE Received | [email protected] |