Tools AI-Found Vulnerability Register aifv-0028
Register entry
GnuTLS heap buffer overflow in certtool, attributed to OpenAI Aardvark
- CVE
- CVE-2025-32990
- Project
- GnuTLS
- Component
- certtool
- Finder
- OpenAI Aardvark
- Autonomy
- agentic security researcher; disclosures filed by OpenAI
- Evidence tier
- Claim outside the record
- Assigner
- Red Hat
- Severity
- 6.5 Medium (CVSS 3.1)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
One of three GnuTLS records published by Red Hat on 10 July 2025 that OpenAI attributes to Aardvark, its agentic security researcher announced in October 2025 and folded into Codex as Codex Security on 6 March 2026. The record itself carries an empty credits array.
Credit as recorded: credits array empty; attribution in OpenAI announcements. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- OpenAI, Introducing Aardvarkopenai.com/index/introducing-aardvark/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026