Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 9 min 99 bronnen 3 kritiek 34 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-42010

HIGH · 7.1 CVSS Gepubliceerd: CWE-170

Beschrijving

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Vendors

Gnu Redhat

Affected products

Gnutls Hardened Images Openshift Container Platform Enterprise Linux

References