CVE-2026-42009
published 2026-05-18CVE-2026-42009: A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.33%
68.0th percentile
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_for_els | — | — |
| redhat | enterprise_linux_for_els | — | — |
| redhat | enterprise_linux_for_els | — | — |
| redhat | enterprise_linux_for_eus | — | — |
| redhat | enterprise_linux_for_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_els | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_els | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_els | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu9.1CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 9.1
CVE-2026-42015 [CRITICAL] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Joshua Rogers discovered that GnuTLS did not properly handle malformed
DTLS handshake fragments in certain cases. A remote attacker could
possibly use this issue to obtain sensitive information, or cause a
denial of service. (CVE-2026-33845)
Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did
not properly validate DTLS handshake fragment lengths in certain cases. A
remote attacker could possibly use this issue to cause GnuTLS to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-33846)
Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly
validate OCSP responses in certain cases. A remote attacker could
possibly use this issue to bypass certi
Red Hat
gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
vendor_redhat·2026-04-29·CVSS 7.5
CVE-2026-42009 [HIGH] CWE-475 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Statement: The impact for this flaw has been downgraded on Red Hat Enterprise Linux due to the following reason:
- The number of elements passed to the vulnerable function at runtime is known and is at most 6 and the element size is sufficiently small. glibc’s qsort implementation will not exercise the quick sort code path, whic
VulDB
GnuTLS Datagram Transport Layer Security Packet undefined behavior for input to api (EUVD-2026-30769)
vuldb·2026-05-18·CVSS 7.5
CVE-2026-42009 [HIGH] GnuTLS Datagram Transport Layer Security Packet undefined behavior for input to api (EUVD-2026-30769)
A vulnerability was found in GnuTLS. It has been classified as problematic. This issue affects some unknown processing of the component Datagram Transport Layer Security Packet Handler. Performing a manipulation results in undefined behavior for input to api.
This vulnerability is reported as CVE-2026-42009. The attack is possible to be carried out remotely. No exploit exists.
GHSA
GHSA-9gx7-g5hv-xjjj: A flaw was found in gnutls
ghsa_unreviewed·2026-05-18
CVE-2026-42009 [HIGH] CWE-475 GHSA-9gx7-g5hv-xjjj: A flaw was found in gnutls
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.
Suricata
ET WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting (CVE-2024-42009)
suricata·2026-01-08·CVSS 9.3
CVE-2024-42009 [CRITICAL] ET WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting (CVE-2024-42009)
ET WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting (CVE-2024-42009)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Roundcube Webmail Cross-Site Scripting (CVE-2024-42009)"; flow:established,to_server; http.request_body; content:"message|3d|"; pcre:"/^.*?\x3cbody\x20[^\x3e]*?\x20on[a-z]+\x3d/R"; content:"email|3d|"; content:"content|3d|html"; fast_pattern; content:"recipient|3d|"; http.method; content:"POST"; reference:url,www.sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/; reference:cve,2024-42009; classtype:web-application-attack; sid:2066621; rev:1; metadata:affected_product Roundcube, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_08, cve CVE_2024_42009, deployment Perimeter
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Bugzilla
CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
bugzilla·2026-05-06·CVSS 7.5
CVE-2026-42009 [HIGH] CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42009 gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
The comparator function used for ordering DTLS packets by sequence numbers did not follow qsort comparator contracts in case of packets with duplicate sequence numbers, which could lead to unstable ordering or undefined behaviour. Return 0 in such cases makes the sorting stable. Additionally, discard packets with same sequence numbers and differing handshake type, so that they don't end up being sorted in the first place.
https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:29794https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34372https://access.redhat.com/errata/RHSA-2026:34764https://access.redhat.com/errata/RHSA-2026:34788https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/security/cve/CVE-2026-42009https://bugzilla.redhat.com/show_bug.cgi?id=2467279https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:29794https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34372https://access.redhat.com/errata/RHSA-2026:34764https://access.redhat.com/errata/RHSA-2026:34788https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/security/cve/CVE-2026-42009https://bugzilla.redhat.com/show_bug.cgi?id=2467279https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json
2026-05-18
Published