CVE-2026-42010
published 2026-05-07CVE-2026-42010: A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character…
PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.05%
60.5th percentile
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| ubuntu | gnutls28 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target servers using RSA-PSK (RSA Pre-Shared Key) TLS cipher suites in GnuTLS — these are the only configurations vulnerable to this authentication bypass. ↗
- →Detect authentication attempts where the supplied PSK username contains an embedded NUL (0x00) byte — this is the crafted payload pattern used to trigger the bypass. ↗
- ·Only GnuTLS servers explicitly configured to use RSA-PSK cipher suites are vulnerable. Servers not using RSA-PSK are not affected by this bypass. ↗
- ·The root cause is a string comparison that stops at the first NUL byte rather than comparing the full username length. The fix requires updating GnuTLS to a version that performs comparison up to the full username length. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu9.1CRITICAL
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 7.5
CVE-2026-33846 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
It was discovered that GnuTLS had a timing side-channel when processing
malformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker
could possibly use this issue to recover sensitive information. This
issue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)
Bing Shi discovered that GnuTLS incorrectly handled decoding certain
DER-encoded certificates. A remote attacker could possibly use this
issue to cause GnuTLS to consume resources, leading to a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)
Luigino Camastra discovered that GnuTLS incorrectly handled certain
PKCS11 token labels. A remote attacker could use this issue to cause
GnuTLS to crash, resulting in a deni
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 9.1
CVE-2026-42015 [CRITICAL] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Joshua Rogers discovered that GnuTLS did not properly handle malformed
DTLS handshake fragments in certain cases. A remote attacker could
possibly use this issue to obtain sensitive information, or cause a
denial of service. (CVE-2026-33845)
Haruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did
not properly validate DTLS handshake fragment lengths in certain cases. A
remote attacker could possibly use this issue to cause GnuTLS to crash,
resulting in a denial of service, or execute arbitrary code.
(CVE-2026-33846)
Oleh Konko and Joshua Rogers discovered that GnuTLS did not properly
validate OCSP responses in certain cases. A remote attacker could
possibly use this issue to bypass certi
Red Hat
gnutls: gnutls: Authentication Bypass via NUL Character in Username
vendor_redhat·2026-04-29·CVSS 7.1
CVE-2026-42010 [HIGH] gnutls: gnutls: Authentication Bypass via NUL Character in Username
gnutls: gnutls: Authentication Bypass via NUL Character in Username
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
Package: gnutls (Red Hat Enterprise Linux 10) - Affected
Package: gnutls (Red Hat Enterprise Linux 6) - Affected
Package: gnutls (Red Hat Enterprise Linux 7) - Affected
Package: gnutls (Red Hat Enterprise Linux 8) - Affected
Package: gnutls (Red Hat Enterprise Linux 9) - Affected
Package: gnutls (Red Hat Hardened I
VulDB
GnuTLS RSA-PSK improper authorization
vuldb·2026-05-17·CVSS 9.8
CVE-2026-42010 [CRITICAL] GnuTLS RSA-PSK improper authorization
A vulnerability marked as critical has been reported in GnuTLS. The impacted element is an unknown function of the component RSA-PSK Handler. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-42010. The attack can be initiated remotely. There is not any exploit available.
GHSA
GHSA-m3r7-xjq8-gc4r: A flaw was found in gnutls
ghsa_unreviewed·2026-05-07
CVE-2026-42010 [HIGH] CWE-626 GHSA-m3r7-xjq8-gc4r: A flaw was found in gnutls
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Bugzilla
CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username
bugzilla·2026-05-06·CVSS 7.1
CVE-2026-42010 [HIGH] CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42010 gnutls: gnutls: Authentication Bypass via NUL Character in Username
libgnutls:
Servers configured with RSA-PSK have wrongfully matched usernames with NUL
character in them to ones truncated to NUL character,
which could lead to an authentication bypass.
Fix the check to perform comparison up to the full username length.
Reported by Joshua Rogers of AISLE Research Team.
[GNUTLS-SA-2026-04-29-4, CVSS: high] [CVE-2026-42010]
https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34764https://access.redhat.com/errata/RHSA-2026:34788https://access.redhat.com/errata/RHSA-2026:34790https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/errata/RHSA-2026:41921https://access.redhat.com/security/cve/CVE-2026-42010https://bugzilla.redhat.com/show_bug.cgi?id=2467289https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4https://access.redhat.com/errata/RHSA-2026:13274https://access.redhat.com/errata/RHSA-2026:20611https://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/errata/RHSA-2026:20613https://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/errata/RHSA-2026:26409https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30004https://access.redhat.com/errata/RHSA-2026:30849https://access.redhat.com/errata/RHSA-2026:30850https://access.redhat.com/errata/RHSA-2026:32962https://access.redhat.com/errata/RHSA-2026:33125https://access.redhat.com/errata/RHSA-2026:34764https://access.redhat.com/errata/RHSA-2026:34788https://access.redhat.com/errata/RHSA-2026:34790https://access.redhat.com/errata/RHSA-2026:36004https://access.redhat.com/errata/RHSA-2026:36005https://access.redhat.com/errata/RHSA-2026:36006https://access.redhat.com/errata/RHSA-2026:41921https://access.redhat.com/security/cve/CVE-2026-42010https://bugzilla.redhat.com/show_bug.cgi?id=2467289https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json
2026-05-07
Published