Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42010

Опубликовано: 07 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.1

Описание

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

РелизСтатусПримечание
devel

pending

3.8.12-2ubuntu1.1
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
fips-preview/jammy

needed

fips-updates/jammy

released

3.7.3-4ubuntu1.9+Fips1
fips-updates/noble

released

3.8.3-1.1ubuntu3.6+Fips1.2
jammy

released

3.7.3-4ubuntu1.9
noble

released

3.8.3-1.1ubuntu3.6

Показывать по

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

CVSS3: 7.1
nvd
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

CVSS3: 7.1
msrc
3 месяца назад

Gnutls: gnutls: authentication bypass via nul character in username

CVSS3: 7.1
debian
3 месяца назад

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest\u2 ...

CVSS3: 9.8
redos
около 1 месяца назад

Уязвимость gnutls

7.1 High

CVSS3