{"id":"AZL-85986","summary":"CVE-2026-3832 affecting package gnutls for versions less than 3.8.3-11","details":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.","modified":"2026-08-28T17:47:58.491253445Z","published":"2026-04-30T18:16:30Z","upstream":["CVE-2026-3832"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832"}],"affected":[{"package":{"name":"gnutls","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gnutls"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.3-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85986.json"}}],"schema_version":"1.9.0"}