Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2026-33307 is a high-severity Stack-based Buffer Overflow (CWE-121) vulnerability in Mod Gnutls Project Mod Gnutls. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SI-10 (Information Input Validation) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2026-33307 is a stack-based buffer overflow vulnerability (CWE-121) in Mod_gnutls, a TLS module for the Apache HTTP Server based on GnuTLS. It affects versions prior to 0.12.3 and 0.13.0. The flaw resides in the client certificate verification code, which imports the certificate chain sent by the client into a fixed-size array of gnutls_x509_crt_t structures without verifying that the number of certificates does not exceed the array size. Although no attacker-controlled data directly overwrites the stack buffer, writing a pointer beyond the array bounds typically causes a segmentation fault, with theoretical potential for stack corruption that has not been observed.
Unauthenticated remote attackers can exploit this vulnerability over the network with low complexity by providing an overly long client certificate chain during the TLS handshake. Exploitation requires server configurations that enable client certificate verification, such as those overriding the default GnuTLSClientVerify ignore setting; default configurations are unaffected. Successful exploitation generally results in a server process crash and denial of service, as indicated by the CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), with no impact on confidentiality or integrity.
The issue is fixed in version 0.12.3 by adding a check on the certificate chain length and rejecting chains that exceed the buffer size, providing a minimal patch for 0.12.x users. Version 0.13.0 addresses it more comprehensively by rewriting certificate verification to use gnutls_certificate_verify_peers(), eliminating the fixed buffer entirely. No workaround exists. See the fix commit at https://github.com/airtower-luna/mod_gnutls/commit/bf4f08c49acae528e97885082cdee460f4534dc1 and the security advisory at https://github.com/airtower-luna/mod_gnutls/security/advisories/GHSA-gjpm-55p4-c76r for further details.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-14692
Vulnerability Data
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t x509[]` array without checking…
more
the number of certificates is less than or equal to the array size. `gnutls_x509_crt_t` is a `typedef` for a pointer to an opaque GnuTLS structure created using with `gnutls_x509_crt_init()` before importing certificate data into it, so no attacker-controlled data was written into the stack buffer, but writing a pointer after the last array element generally triggered a segfault, and could theoretically cause stack corruption otherwise (not observed in practice). Server configurations that do not use client certificates (`GnuTLSClientVerify ignore`, the default) are not affected. The problem has been fixed in version 0.12.3 by checking the length of the provided certificate chain and rejecting it if it exceeds the buffer length, and in version 0.13.0 by rewriting certificate verification to use `gnutls_certificate_verify_peers()`, removing the need for the buffer entirely. There is no workaround. Version 0.12.3 provides the minimal fix for users of 0.12.x who do not wish to upgrade to 0.13.0 yet.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 2 hardening rules · 2 OS baselines
—
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and analysis can discover stack-buffer overflows before deployment.
Input validation directly stops untrusted data from exceeding stack buffer bounds.
Memory-protection mechanisms limit the ability to execute injected code after a stack overflow.
Secure-engineering principles include bounds-checked coding and safe buffer handling that avoid introducing the flaw.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure-development practices directly prevent introduction of stack buffer overflows.
Vulnerability scanning can discover stack buffer overflows but does not prevent their introduction.
Patching eliminates known instances of the weakness after discovery.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing (fuzzing, static analysis) detects stack overflows before release.
Secure SDLC mandates buffer-safety practices that directly prevent stack overflows.
Application security requirements can specify buffer-size and input-validation rules.
Secure architecture principles include memory-safety and least-privilege stack usage.
Secure coding standards explicitly forbid unsafe buffer handling that causes CWE-121.
Change-management gates can enforce security reviews that catch buffer issues.
Hardening callouts derived
Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).
Oracle Linux 8 (1 rule)
- V-248594 OL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. prevents CWE-121
Oracle Linux 9 (1 rule)
- V-271452 OL 9 must use a Linux Security Module configured to enforce limits on system services. prevents CWE-121