Intel

AIKIDO-2026-10210

gnutls.gnutls is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-1584 Published Feb 21, 2026

25

Low Risk

This Affects:

C++gnutls.gnutls
0.0.1 - 3.8.11
Fixed in 3.8.12
Are you affected? Scan for Free

TL;DR

A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gnutls.gnutls is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 3.8.11.

How to fix this

Upgrade the gnutls.gnutls library to the patch version.