{"id":"CVE-2026-67693","title":"An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)","summary":"An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)","severity":"none","published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:33:42.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67693","references":[{"url":"http://gnutls.com","label":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238","label":"cve@mitre.org"},{"url":"https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178","label":"cve@mitre.org"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.189Z","slug":"CVE-2026-67693","body":"## Overview\n\nAn issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}