{"schema_version":1,"title":"GnuTLS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in GnuTLS: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-42014, was published on 16 June 2026.","url":"https://junglewise.ai/threats/technologies/gnutls","json_url":"https://junglewise.ai/threats/technologies/gnutls.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gnutls","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":20,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":15},"latest":[{"cve":"CVE-2026-42014","cvss":6.6,"slug":"cve-2026-42014-gnutls-use-after-free-in-gnutls-pkcs11-token-set-pin","title":"GnuTLS use-after-free in gnutls_pkcs11_token_set_pin","severity":"medium","exploited":false,"published_at":"2026-06-16T02:16:19.14+00:00","url":"https://junglewise.ai/threats/cve-2026-42014-gnutls-use-after-free-in-gnutls-pkcs11-token-set-pin"},{"cve":"CVE-2026-5419","cvss":3.7,"slug":"cve-2026-5419-gnutls-non-constant-time-pkcs-7-padding-check","title":"GnuTLS non-constant-time PKCS#7 padding check","severity":"low","exploited":false,"published_at":"2026-06-01T21:16:47.48+00:00","url":"https://junglewise.ai/threats/cve-2026-5419-gnutls-non-constant-time-pkcs-7-padding-check"},{"cve":"CVE-2026-42015","cvss":5.3,"slug":"cve-2026-42015-gnutls-off-by-one-error-in-pkcs-12-bag-element-bounds-check","title":"GnuTLS off-by-one error in PKCS#12 bag element bounds check","severity":"medium","exploited":false,"published_at":"2026-05-26T22:16:42.18+00:00","url":"https://junglewise.ai/threats/cve-2026-42015-gnutls-off-by-one-error-in-pkcs-12-bag-element-bounds-check"},{"cve":"CVE-2026-42013","cvss":8.2,"slug":"cve-2026-42013-gnutls-certificate-validation-bypass-via-oversized-san-field","title":"GnuTLS certificate validation bypass via oversized SAN field","severity":"high","exploited":false,"published_at":"2026-05-26T22:16:42.05+00:00","url":"https://junglewise.ai/threats/cve-2026-42013-gnutls-certificate-validation-bypass-via-oversized-san-field"},{"cve":"CVE-2026-42012","cvss":7.1,"slug":"cve-2026-42012-gnutls-certificate-validation-bypass-in-uri-and-srv-san-handling","title":"GnuTLS certificate validation bypass in URI and SRV SAN handling","severity":"high","exploited":false,"published_at":"2026-05-26T22:16:41.913+00:00","url":"https://junglewise.ai/threats/cve-2026-42012-gnutls-certificate-validation-bypass-in-uri-and-srv-san-handling"},{"cve":"CVE-2026-42009","cvss":7.5,"slug":"cve-2026-42009-gnutls-denial-of-service-in-dtls-packet-reordering","title":"GnuTLS denial of service in DTLS packet reordering","severity":"high","exploited":false,"published_at":"2026-05-18T13:16:32.707+00:00","url":"https://junglewise.ai/threats/cve-2026-42009-gnutls-denial-of-service-in-dtls-packet-reordering"},{"cve":"CVE-2026-42011","cvss":7.4,"epss":0.0001,"slug":"cve-2026-42011-gnutls-name-constraint-bypass-in-certificate-validation","title":"GnuTLS name constraint bypass in certificate validation","severity":"high","exploited":false,"published_at":"2026-05-07T15:16:09.76+00:00","url":"https://junglewise.ai/threats/cve-2026-42011-gnutls-name-constraint-bypass-in-certificate-validation"},{"cve":"CVE-2026-42010","cvss":7.1,"epss":0.0007,"slug":"cve-2026-42010-gnutls-authentication-bypass-in-rsa-psk-username-handling","title":"GnuTLS authentication bypass in RSA-PSK username handling","severity":"high","exploited":false,"published_at":"2026-05-07T12:16:17.977+00:00","url":"https://junglewise.ai/threats/cve-2026-42010-gnutls-authentication-bypass-in-rsa-psk-username-handling"},{"cve":"CVE-2026-33846","cvss":7.5,"epss":0.0003,"slug":"cve-2026-33846-gnutls-heap-buffer-overflow-in-dtls-handshake-reassembly","title":"GnuTLS heap buffer overflow in DTLS handshake reassembly","severity":"high","exploited":false,"published_at":"2026-05-04T10:15:59.69+00:00","url":"https://junglewise.ai/threats/cve-2026-33846-gnutls-heap-buffer-overflow-in-dtls-handshake-reassembly"},{"cve":"CVE-2026-3833","cvss":6.5,"epss":0.001,"slug":"cve-2026-3833-gnutls-policy-bypass-in-nameconstraints-comparison","title":"GnuTLS policy bypass in nameConstraints comparison","severity":"medium","exploited":false,"published_at":"2026-04-30T18:16:30.577+00:00","url":"https://junglewise.ai/threats/cve-2026-3833-gnutls-policy-bypass-in-nameconstraints-comparison"},{"cve":"CVE-2026-3832","cvss":3.7,"epss":0.0002,"slug":"cve-2026-3832-gnutls-certificate-revocation-bypass-in-ocsp-response-handling","title":"GnuTLS certificate revocation bypass in OCSP response handling","severity":"low","exploited":false,"published_at":"2026-04-30T18:16:30.433+00:00","url":"https://junglewise.ai/threats/cve-2026-3832-gnutls-certificate-revocation-bypass-in-ocsp-response-handling"},{"cve":"CVE-2026-33845","cvss":7.5,"epss":0.0006,"slug":"cve-2026-33845-gnutls-integer-underflow-in-dtls-handshake-parsing","title":"GnuTLS integer underflow in DTLS handshake parsing","severity":"high","exploited":false,"published_at":"2026-04-30T18:16:28.003+00:00","url":"https://junglewise.ai/threats/cve-2026-33845-gnutls-integer-underflow-in-dtls-handshake-parsing"},{"cve":"CVE-2026-1584","cvss":7.5,"epss":0.0133,"slug":"cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification","title":"GnuTLS NULL pointer dereference in PSK binder verification","severity":"high","exploited":false,"published_at":"2026-04-09T18:16:44.047+00:00","url":"https://junglewise.ai/threats/cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification"},{"cve":"CVE-2025-14831","cvss":5.3,"epss":0.0006,"slug":"cve-2025-14831-gnutls-denial-of-service-via-excessive-resource-consumption","title":"GnuTLS denial of service via excessive resource consumption during certificate verification","severity":"medium","exploited":false,"published_at":"2026-02-09T15:16:09.937+00:00","url":"https://junglewise.ai/threats/cve-2025-14831-gnutls-denial-of-service-via-excessive-resource-consumption"},{"cve":"CVE-2025-9820","cvss":4,"epss":0.002,"slug":"cve-2025-9820-gnutls-stack-overflow-in-gnutls-pkcs11-token-init","title":"GnuTLS stack overflow in gnutls_pkcs11_token_init","severity":"medium","exploited":false,"published_at":"2026-01-26T20:16:09.37+00:00","url":"https://junglewise.ai/threats/cve-2025-9820-gnutls-stack-overflow-in-gnutls-pkcs11-token-init"},{"cve":"CVE-2025-6395","cvss":6.5,"epss":0.0062,"slug":"cve-2025-6395-gnutls-null-pointer-dereference-in-gnutls-figure-common","title":"GnuTLS NULL pointer dereference in _gnutls_figure_common_ciphersuite","severity":"medium","exploited":false,"published_at":"2025-07-10T16:15:25.11+00:00","url":"https://junglewise.ai/threats/cve-2025-6395-gnutls-null-pointer-dereference-in-gnutls-figure-common"},{"cve":"CVE-2025-32990","cvss":6.5,"epss":0.0072,"slug":"cve-2025-32990-gnutls-certtool-heap-buffer-overflow-in-template-parsing","title":"GnuTLS certtool heap buffer overflow in template parsing","severity":"medium","exploited":false,"published_at":"2025-07-10T10:15:33.06+00:00","url":"https://junglewise.ai/threats/cve-2025-32990-gnutls-certtool-heap-buffer-overflow-in-template-parsing"},{"cve":"CVE-2025-32989","cvss":5.3,"epss":0.0118,"slug":"cve-2025-32989-gnutls-heap-buffer-overread-in-sct-extension-parsing","title":"GnuTLS heap buffer overread in SCT extension parsing","severity":"medium","exploited":false,"published_at":"2025-07-10T08:15:24.43+00:00","url":"https://junglewise.ai/threats/cve-2025-32989-gnutls-heap-buffer-overread-in-sct-extension-parsing"},{"cve":"CVE-2025-32988","cvss":6.5,"epss":0.0119,"slug":"cve-2025-32988-gnutls-double-free-in-subject-alternative-name-export-logic","title":"GnuTLS double-free in Subject Alternative Name export logic","severity":"medium","exploited":false,"published_at":"2025-07-10T08:15:24.223+00:00","url":"https://junglewise.ai/threats/cve-2025-32988-gnutls-double-free-in-subject-alternative-name-export-logic"},{"cve":"CVE-2024-12243","cvss":5.3,"slug":"cve-2024-12243-gnutls-denial-of-service-via-inefficient-der-decoding-in-libtasn1","title":"GnuTLS denial of service via inefficient DER decoding in libtasn1","severity":"medium","exploited":false,"published_at":"2025-02-10T16:15:37.423+00:00","url":"https://junglewise.ai/threats/cve-2024-12243-gnutls-denial-of-service-via-inefficient-der-decoding-in-libtasn1"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Gnu Binutils","slug":"binutils","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/binutils"},{"name":"Gnu Glibc","slug":"glibc","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/glibc"},{"name":"Gnu LibreDWG","slug":"libredwg","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/libredwg"},{"name":"GNU tar","slug":"tar","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tar"},{"name":"Gnu Bash","slug":"bash","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/bash"},{"name":"GNU C Library","slug":"gnu-c-library","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/gnu-c-library"},{"name":"Gnu Emacs","slug":"emacs","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/emacs"},{"name":"Gnu Wget","slug":"wget","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/wget"},{"name":"Gnu Grub2","slug":"grub2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/grub2"},{"name":"GNU Coreutils","slug":"coreutils","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/coreutils"},{"name":"Gnu Cpio","slug":"cpio","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/cpio"},{"name":"Gnu Gawk","slug":"gawk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gawk"}],"technology":{"hub":true,"name":"GnuTLS","slug":"gnutls","vendor":{"name":"Gnu","slug":"gnu","url":"https://junglewise.ai/threats/vendors/gnu"},"aliases":[],"category":"library","homepage":"https://www.gnutls.org/","repo_url":"https://gitlab.com/gnutls/gnutls","description":"GnuTLS is a secure communications library implementing the TLS and SSL protocols and APIs to access the relevant security applications.","url":"https://junglewise.ai/threats/technologies/gnutls"},"most_severe":[{"cve":"CVE-2026-42013","cvss":8.2,"slug":"cve-2026-42013-gnutls-certificate-validation-bypass-via-oversized-san-field","title":"GnuTLS certificate validation bypass via oversized SAN field","severity":"high","exploited":false,"published_at":"2026-05-26T22:16:42.05+00:00","url":"https://junglewise.ai/threats/cve-2026-42013-gnutls-certificate-validation-bypass-via-oversized-san-field"},{"cve":"CVE-2026-1584","cvss":7.5,"epss":0.0133,"slug":"cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification","title":"GnuTLS NULL pointer dereference in PSK binder verification","severity":"high","exploited":false,"published_at":"2026-04-09T18:16:44.047+00:00","url":"https://junglewise.ai/threats/cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification"},{"cve":"CVE-2026-33845","cvss":7.5,"epss":0.0006,"slug":"cve-2026-33845-gnutls-integer-underflow-in-dtls-handshake-parsing","title":"GnuTLS integer underflow in DTLS handshake parsing","severity":"high","exploited":false,"published_at":"2026-04-30T18:16:28.003+00:00","url":"https://junglewise.ai/threats/cve-2026-33845-gnutls-integer-underflow-in-dtls-handshake-parsing"},{"cve":"CVE-2026-33846","cvss":7.5,"epss":0.0003,"slug":"cve-2026-33846-gnutls-heap-buffer-overflow-in-dtls-handshake-reassembly","title":"GnuTLS heap buffer overflow in DTLS handshake reassembly","severity":"high","exploited":false,"published_at":"2026-05-04T10:15:59.69+00:00","url":"https://junglewise.ai/threats/cve-2026-33846-gnutls-heap-buffer-overflow-in-dtls-handshake-reassembly"},{"cve":"CVE-2026-42009","cvss":7.5,"slug":"cve-2026-42009-gnutls-denial-of-service-in-dtls-packet-reordering","title":"GnuTLS denial of service in DTLS packet reordering","severity":"high","exploited":false,"published_at":"2026-05-18T13:16:32.707+00:00","url":"https://junglewise.ai/threats/cve-2026-42009-gnutls-denial-of-service-in-dtls-packet-reordering"},{"cve":"CVE-2026-42011","cvss":7.4,"epss":0.0001,"slug":"cve-2026-42011-gnutls-name-constraint-bypass-in-certificate-validation","title":"GnuTLS name constraint bypass in certificate validation","severity":"high","exploited":false,"published_at":"2026-05-07T15:16:09.76+00:00","url":"https://junglewise.ai/threats/cve-2026-42011-gnutls-name-constraint-bypass-in-certificate-validation"},{"cve":"CVE-2026-42010","cvss":7.1,"epss":0.0007,"slug":"cve-2026-42010-gnutls-authentication-bypass-in-rsa-psk-username-handling","title":"GnuTLS authentication bypass in RSA-PSK username handling","severity":"high","exploited":false,"published_at":"2026-05-07T12:16:17.977+00:00","url":"https://junglewise.ai/threats/cve-2026-42010-gnutls-authentication-bypass-in-rsa-psk-username-handling"},{"cve":"CVE-2026-42012","cvss":7.1,"slug":"cve-2026-42012-gnutls-certificate-validation-bypass-in-uri-and-srv-san-handling","title":"GnuTLS certificate validation bypass in URI and SRV SAN handling","severity":"high","exploited":false,"published_at":"2026-05-26T22:16:41.913+00:00","url":"https://junglewise.ai/threats/cve-2026-42012-gnutls-certificate-validation-bypass-in-uri-and-srv-san-handling"},{"cve":"CVE-2026-42014","cvss":6.6,"slug":"cve-2026-42014-gnutls-use-after-free-in-gnutls-pkcs11-token-set-pin","title":"GnuTLS use-after-free in gnutls_pkcs11_token_set_pin","severity":"medium","exploited":false,"published_at":"2026-06-16T02:16:19.14+00:00","url":"https://junglewise.ai/threats/cve-2026-42014-gnutls-use-after-free-in-gnutls-pkcs11-token-set-pin"},{"cve":"CVE-2025-32988","cvss":6.5,"epss":0.0119,"slug":"cve-2025-32988-gnutls-double-free-in-subject-alternative-name-export-logic","title":"GnuTLS double-free in Subject Alternative Name export logic","severity":"medium","exploited":false,"published_at":"2025-07-10T08:15:24.223+00:00","url":"https://junglewise.ai/threats/cve-2025-32988-gnutls-double-free-in-subject-alternative-name-export-logic"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}