<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:49:10.415520+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09660</id>
    <title>bdu:2026-09660</title>
    <updated>2026-10-02T21:49:10.473501+00:00</updated>
    <content>bdu:2026-09660</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09660"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42012</id>
    <title>BELL-CVE-2026-42012</title>
    <updated>2026-10-02T21:49:10.473560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</id>
    <title>certfr-2026-avi-0737 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T21:49:10.473597+00:00</updated>
    <content>certfr-2026-avi-0737</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382047</id>
    <title>EUVD-2026-382047</title>
    <updated>2026-10-02T21:49:10.473615+00:00</updated>
    <content>EUVD-2026-382047</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42012</id>
    <title>fkie_cve-2026-42012</title>
    <updated>2026-10-02T21:49:10.473626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7hhj-8fwv-m5hc</id>
    <title>GHSA-7hhj-8fwv-m5hc</title>
    <updated>2026-10-02T21:49:10.473652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7hhj-8fwv-m5hc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42012</id>
    <title>msrc_CVE-2026-42012 — Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans</title>
    <updated>2026-10-02T21:49:10.473668+00:00</updated>
    <content>msrc_CVE-2026-42012</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3118</id>
    <title>OESA-2026-3118 — gnutls security update</title>
    <updated>2026-10-02T21:49:10.473689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: gnutls</p>
<p>GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.

Security Fix(es):</p>
<p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)</p>
<p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1</id>
    <title>openSUSE-SU-2026:10691-1 — gnutls-3.8.13-1.1 on GA media</title>
    <updated>2026-10-02T21:49:10.473719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls-3.8.13-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13274</id>
    <title>RHSA-2026:13274 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T21:49:10.473742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:20612</id>
    <title>RLSA-2026:20612 — Important: gnutls security update</title>
    <updated>2026-10-02T21:49:10.473779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: gnutls</p>
<p>The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library,
which implements cryptographic algorithms and protocols such as SSL, TLS, and
DTLS.</p>
<p>Security Fix(es):</p>
<p>* gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
* gnutls: Fix crashing on an underflow with a DTLS datagram
(CVE-2026-33845)
* gnutls: Fix RSA-PSK identity truncation (CVE-2026-42010)
* gnutls: Fix case-sensitivity of domain name comparison in name
constraints (CVE-2026-3833)
* gnutls: Fix intersecting empty name constraints (CVE-2026-42011)
* gnutls: Denial of Service via heap buffer overflow in DTLS handshake
fragment reassembly (CVE-2026-33846)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:20612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1</id>
    <title>SUSE-SU-2026:21752-1 — Security update for gnutls</title>
    <updated>2026-10-02T21:49:10.473805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for gnutls</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42012</id>
    <title>UBUNTU-CVE-2026-42012</title>
    <updated>2026-10-02T21:49:10.473825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28, Ubuntu:26.04:LTS: gnutls28</p>
<p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-088</id>
    <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
    <updated>2026-10-02T21:49:10.473858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.</p>
<p>The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25</p>
<p>All other vulnerabilities are to be fixed in the upcoming releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312</id>
    <title>WID-SEC-W-2026-1312 — GnuTLS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:49:10.473900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312"/>
  </entry>
</feed>
