Case-Sensitive Comparison Flaw in GnuTLS Affects Remote Security
CVE-2026-3833
6.5MEDIUM
What is CVE-2026-3833?
A vulnerability in GnuTLS arises from its case-sensitive comparison of nameConstraints labels for DNS and email constraints. This design flaw enables an attacker to exploit the system by creating a specially crafted leaf certificate that utilizes varying casing in the Subject Alternative Name (SAN). Consequently, this can lead to a policy bypass wherein a certificate that should ideally be rejected is accepted, posing risks of unauthorized access and potential information disclosure.