Improper Certificate Validation in GnuTLS - CVE-2026-3832
Published: April 30, 2026
GnuTLS
GnuTLS
Description
The vulnerability allows a remote attacker to bypass certificate revocation checks.
The vulnerability exists due to improper certificate status validation in OCSP response processing when validating a certificate against a multi-entry OCSP response. A remote attacker can supply a certificate status response with multiple entries to bypass certificate revocation checks.