{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gnutls-vulnerable-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-0553"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GnuTLS (vulnerable versions)","GnuTLS"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","transport-security"],"_cs_type":"advisory","_cs_vendors":["GnuTLS"],"content_html":"\u003cp\u003eThe GnuTLS library, a widely used implementation of the TLS protocol, contains a vulnerability identified as CVE-2024-0553. This flaw permits a remote, unauthenticated attacker to induce a denial of service (DoS) state in applications that depend on the affected versions of the GnuTLS library. Because GnuTLS is a foundational cryptographic component used by numerous client and server-side applications across Linux, macOS, and Windows environments, the potential for service disruption is broad. Defenders should prioritize auditing the GnuTLS versions bundled with critical network services, mail servers, and internal applications to ensure patching or mitigation once vendor-specific updates are available. The vulnerability emphasizes the risk posed by weaknesses in low-level cryptographic libraries which can be exploited to crash processes or exhaust system resources without requiring prior authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability results in an application-level denial of service. Depending on the architecture of the host application, this could lead to the crash of critical network services, the suspension of secure communications, or the unavailability of services reliant on TLS termination. This vulnerability poses a significant risk to the availability of infrastructure in any sector utilizing GnuTLS for secure data transmission.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify applications within the environment that dynamically or statically link against the vulnerable GnuTLS library versions using software composition analysis (SCA) or vulnerability scanners.\u003c/li\u003e\n\u003cli\u003ePrioritize patching for internet-facing services that utilize GnuTLS to prevent remote exploitation.\u003c/li\u003e\n\u003cli\u003eMonitor service health and application logs for unexpected crashes or service restarts that may indicate exploitation attempts (CVE-2024-0553).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:04:26Z","date_published":"2026-09-01T12:00:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gnutls-dos/","summary":"A vulnerability in the GnuTLS library allows remote, unauthenticated attackers to trigger a denial of service condition in applications leveraging the library via CVE-2024-0553.","title":"GnuTLS Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-gnutls-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - GnuTLS (Vulnerable Versions)","version":"https://jsonfeed.org/version/1.1"}