Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42010

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10gnutlsFixedRHSA-2026:2061326.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgnutlsFixedRHSA-2026:2640916.06.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2026:2061126.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OngnutlsFixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-170
https://bugzilla.redhat.com/show_bug.cgi?id=2467289gnutls: gnutls: Authentication Bypass via NUL Character in Username

EPSS

Процентиль: 61%
0.0105
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

CVSS3: 7.1
nvd
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

CVSS3: 7.1
msrc
3 месяца назад

Gnutls: gnutls: authentication bypass via nul character in username

CVSS3: 7.1
debian
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest\u2 ...

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость gnutls

EPSS

Процентиль: 61%
0.0105
Низкий

7.1 High

CVSS3