FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mod_gnutls -- multiple vulnerabilities

Affected packages
ap24-mod_gnutls < 0.13.0

Details

VuXML ID a7b4cdfc-9f9d-11f1-a655-3497f65b111b
Discovery 2026-03-20
Entry 2026-08-24

The mod_gnutls project reports:

Security fix (CVE-2026-33307): Fix out-of-bounds write when receiving a client certificate chain longer than the buffer.

Security fix (CVE-2026-33308): Check Key Purpose during client certificate verification.

References

CVE Name CVE-2026-33307
CVE Name CVE-2026-33308
URL https://github.com/airtower-luna/mod_gnutls/security/advisories/GHSA-gjpm-55p4-c76r
URL https://github.com/airtower-luna/mod_gnutls/security/advisories/GHSA-hm2g-m958-8qgh