CVE-2026-67693
Awaiting Analysis Awaiting Analysis - Queue

Incorrect X.509 Certificate Validation in GnuTLS Leading to Sensitive Information Disclosure

Vulnerability report for CVE-2026-67693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GnuTLS v3.8.13 allows an attacker to potentially access sensitive information. The issue occurs when the library fails to properly reject X.509 certificates that have conflicting Key Usage (KU) and Extended Key Usage (EKU) extensions. This contradiction could be exploited to bypass intended security restrictions.

Detection Guidance

To detect this vulnerability, inspect GnuTLS version 3.8.13 systems for improper certificate validation. Check certificates with critical Key Usage extensions where all bits are cleared and Extended Key Usage includes serverAuth. Use OpenSSL or GnuTLS tools to examine certificate extensions and validate Key Usage enforcement.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to sensitive data protected by the affected GnuTLS implementation. Attackers might intercept or decrypt communications, impersonate servers, or gain access to protected resources by presenting maliciously crafted certificates.

Compliance Impact

This vulnerability could lead to violations of data protection regulations like GDPR or HIPAA by enabling unauthorized access to personal or health data. Organizations using affected GnuTLS versions may fail compliance audits if they cannot demonstrate proper certificate validation.

Mitigation Strategies

Upgrade GnuTLS to a patched version beyond 3.8.13. Temporarily disable certificate validation for affected systems if immediate upgrade is not possible. Review and revoke any certificates with contradictory Key Usage and Extended Key Usage extensions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67693. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart