Mod Gnutls Project maintains mod_gnutls, an Apache module that integrates the GnuTLS cryptographic library for TLS termination, and operates within a narrowly scoped vulnerability footprint. Its observed weakness classes center on certificate validation logic, control-flow issues in cryptographic handling, and memory safety in native code, reflecting the demands of secure protocol implementation at the Apache layer. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mod Gnutls Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33307HIGH Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by | Mar 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-25824HIGH Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the tr | Feb 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2009-5144HIGH mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certi | Feb 3, 2018 | 7.5 | 24 | NO | NO |
CVE-2026-33308MEDIUM Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended | Mar 24, 2026 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mod Gnutls Project.
Media articles that mention a CVE ID that affects a product developed by Mod Gnutls Project — matched by CVE ID, not by vendor name.