CVE-2026-42010
Executive Summary
CVE-2026-42010 exposes a flaw in GnuTLS where RSA‑PSK servers incorrectly truncate usernames containing a NUL byte, allowing a remote attacker to craft a username that bypasses authentication. The vulnerability can be leveraged to gain unauthorized access to TLS‑protected services without valid credentials. No current KEV listing, but mitigations include updating GnuTLS to patched versions or disabling RSA‑PSK.
Authoritative CVE Metadata - CVSS Base Score: 7.1 (HIGH) - Published: 2026-05-07T12:16:17.977 - Last Modified: 2026-09-28T02:17:26.550
Original Description: A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
"Sooner or later, those who win are those who think they can."
— Richard Bach