CVE-2026-42010

Source
https://cve.org/CVERecord?id=CVE-2026-42010
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42010.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-42010
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (3)
DEBIAN (1)
ECHO (1)
OESA (5)
openSUSE (2)
RHSA (11)
RLSA (3)
ROOT (2)
SUSE (7)
UBUNTU (1)
Related
Published
2026-05-07T12:00:05Z
Modified
2026-10-02T11:46:00Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Gnutls: gnutls: authentication bypass via nul character in username
Details

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-170"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42010.json"
}
References

Affected packages

Git / gitlab.com/gnutls/gnutls

Affected ranges

Type
GIT
Repo
https://gitlab.com/gnutls/gnutls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
0
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42010.json"