{"id":12644,"date":"2026-05-06T10:03:36","date_gmt":"2026-05-06T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/06\/gnutls-3-8-13-released-with-fix-for-12-vulnerabilities-affecting-network-communications\/"},"modified":"2026-05-06T10:03:36","modified_gmt":"2026-05-06T10:03:36","slug":"gnutls-3-8-13-released-with-fix-for-12-vulnerabilities-affecting-network-communications","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/06\/gnutls-3-8-13-released-with-fix-for-12-vulnerabilities-affecting-network-communications\/","title":{"rendered":"GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications"},"content":{"rendered":"<p>    GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications.<\/p>\n<p>The update is highly recommended for all <a href=\"https:\/\/cybersecuritynews.com\/marvin-attack-rsa-decryption-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">systems using GnuTLS<\/a>, as it addresses memory corruption, authentication bypasses, and certificate validation errors.<\/p>\n<p>Four vulnerabilities discovered in this release are categorized as High severity and require immediate attention from security teams.<\/p>\n<p>These critical flaws primarily impact the <a href=\"https:\/\/cybersecuritynews.com\/brain-cipher-ransomware-analysis-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">Datagram Transport Layer Security (DTLS)<\/a> implementation and specific authentication configurations.<\/p>\n<p>Threat actors often target these types of <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-update-8-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">memory corruption and bypass vulnerabilities<\/a> to compromise remote servers or disrupt services.<\/p>\n<p>The update fixes a wide range of bugs, from timing side channels to critical heap overruns.<\/p>\n<p> The table below highlights the most significant vulnerabilities patched in version 3.8.13:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Severity<\/th>\n<th>Issue Type<\/th>\n<th>Summary<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE-2026-33846<\/strong><\/td>\n<td>High<\/td>\n<td>Heap Overwrite<\/td>\n<td>Missing checks could let attackers overwrite memory.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-42010<\/strong><\/td>\n<td>High<\/td>\n<td>Auth Bypass<\/td>\n<td>Flawed username handling allows login bypass.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-33845<\/strong><\/td>\n<td>High<\/td>\n<td>Heap Overrun<\/td>\n<td>Memory error may let attackers overflow data remotely.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-42009<\/strong><\/td>\n<td>High<\/td>\n<td>Undefined Behavior<\/td>\n<td>Packet sorting flaw may cause unpredictable issues.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-42013<\/strong><\/td>\n<td>Medium<\/td>\n<td>Cert Validation Issue<\/td>\n<td>Improper certificate checks could weaken security.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-42014<\/strong><\/td>\n<td>Medium<\/td>\n<td>Use-After-Free<\/td>\n<td>Memory bug triggered during PIN changes.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-3833<\/strong><\/td>\n<td>Moderate<\/td>\n<td>Constraint Bypass<\/td>\n<td>Domain checks ignore case rules, risking validation bypass.<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-5419<\/strong><\/td>\n<td>Low<\/td>\n<td>Timing Leak<\/td>\n<td>Timing flaw may expose sensitive information.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><a href=\"https:\/\/www.gnutls.org\/security-new.html#GNUTLS-SA-2026-04-29-1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to the GnuTLS Security Advisory 2026<\/a>, admins should upgrade to GnuTLS 3.8.13 to mitigate these threats.<\/p>\n<p>Public-facing servers utilizing DTLS or RSA-PSK authentication are at the highest risk. They should be patched during the next available maintenance window.<\/p>\n<p>To proactively defend, security operations centers should update their monitoring tools to detect anomalous DTLS traffic or malformed RSA-PSK authentication attempts.<\/p>\n<p>Ensuring that foundational cryptographic libraries remain up to date is a critical strategy for preventing initial network compromise.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gnutls-3-8-13-released\/\">GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gnutls-3-8-13-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications. The update is highly recommended for all systems using GnuTLS, as it addresses memory corruption, authentication bypasses, and certificate validation errors. Four vulnerabilities discovered [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-12644","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12644"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12644"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12644\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}