Research / Finding
Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response F-GNUTLS-OCSP-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
—score not recorded
Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
Fixed in: GnuTLS 3.8.13
patched
details
Finding IDs F-GNUTLS-OCSP-001 CVE CVE-2026-3832 Status patched Fixed in GnuTLS 3.8.13 Recorded credit independently reported by Oleh Konko (1seal) and Joshua Rogers Note cert-session: fix multi-entry OCSP revocation bypass CVE registry state PUBLISHED CVE state checked 23 Sep 2026 F-GNUTLS-OCSP-001: Verification failures. Multi-entry OCSP processing can miss a revoked status. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-GNUTLS-OCSP-001
Security area (1seal assessment): Identity. Multi-entry OCSP processing can miss a revoked status. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .