Gnutls
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
75
Total CVEs
More Total CVEs than 99% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gnutls over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
May 18, 2026
67 days ago
CVE Severity & Scoring
Gnutls75 CVEs
48%
40%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.3%)
Network36 (48.0%)
Unknown37 (49.3%)
Physical1 (1.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (34.7%)
High12 (16.0%)
Unknown37 (49.3%)
User Interaction
None38 (50.7%)
Unknown37 (49.3%)
Required0 (0.0%)
Privileges Required
Low3 (4.0%)
High0 (0.0%)
None35 (46.7%)
Unknown37 (49.3%)
Top CVEs
Signals from CVEs in this product scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
CVE-2019-3829HIGH A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server appl | Mar 27, 2019 | 7.5 | 57 | NO | NO |
CVE-2026-42010CRITICAL A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated username | May 7, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-33845CRITICAL A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-o | Apr 30, 2026 | 9.1 | 40 | NO | NO |
CVE-2017-5334CRITICAL Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted | Mar 24, 2017 | 9.8 | 40 | NO | NO |
CVE-2014-0092MEDIUM lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-i | Mar 7, 2014 | 5.8 | 38 | NO | NO |
CVE-2012-1663HIGH Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact vi | Mar 13, 2012 | 7.5 | 36 | NO | YES |
CVE-2026-42009HIGH A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible f | May 18, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-3833HIGH A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Nam | Apr 30, 2026 | 7.4 | 34 | NO | NO |
CVE-2017-5336CRITICAL Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impa | Mar 24, 2017 | 9.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (75 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
5.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (75 CVEs).
Media Mentions
Signals from CVEs in this product scope (75 CVEs).
Top CNAs Publishing CVEs For Gnutls
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6.8-11.el8_2 | 1 | 7.4 | 1.4% | 0 | 0 |
| 3.5.7 | 4 | 9.2 | 13.5% | 0 | 0 |
| 3.5.6 | 4 | 9.2 | 13.5% | 0 | 0 |
| 3.5.5 | 4 | 9.2 | 13.5% | 0 | 0 |
| 3.5.4 | 4 | 9.2 | 13.5% | 0 | 0 |
| 3.5.3 | 5 | 8.9 | 11.3% | 0 | 0 |
| 3.5.2 | 5 | 8.9 | 11.3% | 0 | 0 |
| 3.5.1 | 5 | 8.9 | 11.3% | 0 | 0 |
| 3.5.0 | 5 | 8.9 | 11.3% | 0 | 0 |
| 3.4.3 | 1 | 5.0 | 19.0% | 0 | 0 |
| 3.4.2 | 1 | 5.0 | 19.0% | 0 | 0 |
| 3.4.12 | 1 | 7.5 | 2.2% | 0 | 0 |
| 3.4.1 | 1 | 5.0 | 19.0% | 0 | 0 |
| 3.4.0 | 1 | 5.0 | 19.0% | 0 | 0 |
| 3.3.9 | 2 | 5.0 | 11.2% | 0 | 0 |
| 3.3.8 | 2 | 5.0 | 11.2% | 0 | 0 |
| 3.3.7 | 2 | 5.0 | 11.2% | 0 | 0 |
| 3.3.6 | 2 | 5.0 | 11.2% | 0 | 0 |
| 3.3.5 | 2 | 5.0 | 11.2% | 0 | 0 |
| 3.3.4 | 2 | 5.0 | 11.2% | 0 | 0 |