CVE-2025-14831

A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Configurations

No configuration.

History

05 May 2026, 18:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:13812 -

22 Apr 2026, 19:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7477 -

17 Apr 2026, 14:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8746 -
  • () https://access.redhat.com/errata/RHSA-2026:8748 -

17 Apr 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:8747 -

09 Apr 2026, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7335 -

09 Apr 2026, 16:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7329 -

07 Apr 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:6738 -

07 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:6737 -

06 Apr 2026, 11:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:6618 -

06 Apr 2026, 08:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:6630 -

24 Mar 2026, 11:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:5585 -
  • () https://access.redhat.com/errata/RHSA-2026:5606 -

18 Mar 2026, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:4943 -

16 Mar 2026, 20:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:4655 -

12 Mar 2026, 18:16

Type Values Removed Values Added
References
  • () https://gitlab.com/gnutls/gnutls/-/issues/1773 -

11 Mar 2026, 09:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:4188 -

02 Mar 2026, 17:16

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en GnuTLS. Esta vulnerabilidad permite una denegación de servicio (DoS) mediante un consumo excesivo de CPU (Unidad Central de Procesamiento) y memoria a través de certificados maliciosos especialmente diseñados que contienen un gran número de restricciones de nombre y nombres alternativos del sujeto (SANs).
References
  • () https://access.redhat.com/errata/RHSA-2026:3477 -

09 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 15:16

Updated : 2026-05-05 18:16


NVD link : CVE-2025-14831

Mitre link : CVE-2025-14831

CVE.ORG link : CVE-2025-14831


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity