YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0028

Register entry

GnuTLS heap buffer overflow in certtool, attributed to OpenAI Aardvark

CVE
CVE-2025-32990
Project
GnuTLS
Component
certtool
Finder
OpenAI Aardvark
Autonomy
agentic security researcher; disclosures filed by OpenAI
Evidence tier
Claim outside the record
Assigner
Red Hat
Severity
6.5 Medium (CVSS 3.1)
Bounty
None published
Confidence
CONFIRMED

What happened

One of three GnuTLS records published by Red Hat on 10 July 2025 that OpenAI attributes to Aardvark, its agentic security researcher announced in October 2025 and folded into Codex as Codex Security on 6 March 2026. The record itself carries an empty credits array.

Credit as recorded: credits array empty; attribution in OpenAI announcements. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026