CVE-2026-67693: GNUTLS GNUTLS vulnerability
Published Oct 8, 2026
·Updated
An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)
Affected Software
1 affected component
GNUTLS GNUTLS=3.8.13
Event History
Oct 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What certificate condition is required for exploitation?
The end-entity X.509 certificate must contain a contradictory combination of Key Usage and Extended Key Usage values. The issue is that GnuTLS 3.8.13 fails to reject such certificates during verification.
2
What is the potential impact?
An attacker may obtain sensitive information if they can use an end-entity certificate with the contradictory KU and EKU combination described.