EXPOSURES › CVE-2026-33845
CVE-2026-33845
HIGH
DETAIL
SourceNVD · cve
Published2026-04-30
CVSS7.5
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-33845 ↗
SHAME 25/100
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.