---
id: CVE-2026-67693
title: >-
  An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information
  via failing to reject end-entity X.509 certificates that contain a
  contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)
summary: >-
  An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information
  via failing to reject end-entity X.509 certificates that contain a
  contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)
severity: none
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:33:42.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67693'
references:
  - url: 'http://gnutls.com'
    label: cve@mitre.org
  - url: 'https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238'
    label: cve@mitre.org
  - url: >-
      https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178
    label: cve@mitre.org
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.189Z'
---

## Overview

An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
