CVE-2026-95209
Awaiting Analysis Awaiting Analysis - Queue

GnuTLS CA Certificate Validation Denial of Service

Vulnerability report for CVE-2026-95209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GnuTLS v3.8.13 causes legitimate Certificate Authority (CA) certificates to be incorrectly rejected. This leads to a Denial of Service (DoS) because systems using GnuTLS cannot verify trusted certificates, disrupting secure communications and authentication processes.

Detection Guidance

Check GnuTLS version with 'gnutls-cli --version' or 'dpkg -l | grep gnutls'. If version 3.8.13 is installed, the system is vulnerable. Inspect certificate chains for CA constraints and missing SANs using 'openssl verify -verbose -CAfile <ca-cert> <server-cert>'.

Impact Analysis

If you use systems or applications relying on GnuTLS v3.8.13, this vulnerability could prevent secure connections from being established. This may result in service disruptions, failed authentication attempts, or inability to access critical services that depend on certificate validation.

Compliance Impact

This vulnerability could impact compliance by disrupting secure data transmission and authentication. For GDPR, it may affect data integrity and confidentiality requirements. For HIPAA, it could compromise secure communications in healthcare systems, potentially violating privacy and security rules.

Mitigation Strategies

Upgrade GnuTLS to a patched version if available. Temporarily disable strict certificate validation in GnuTLS clients if feasible. Replace affected CA certificates with ones that do not enforce dNSName constraints without SANs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart