Ghostwire

CVE-2026-67693: An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509...

HIGH CVSS 0.0 EPSS 0.11%

Published: October 8, 2026 | Last Modified: October 8, 2026

Description

An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.11% (1th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References