<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T00:33:01.894249+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-42010</id>
    <title>CVE-2026-42010 — Gnutls: gnutls: authentication bypass via nul character in username</title>
    <updated>2026-10-09T00:33:02.123668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> gnutls, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and 24 more</p>
<p>A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-42010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m3r7-xjq8-gc4r</id>
    <title>GHSA-m3r7-xjq8-gc4r</title>
    <updated>2026-10-09T00:33:02.123822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m3r7-xjq8-gc4r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13274</id>
    <title>RHSA-2026:13274 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-09T00:33:02.123845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:20611</id>
    <title>RHSA-2026:20611 — Red Hat Security Advisory: gnutls security update</title>
    <updated>2026-10-09T00:33:02.123885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:20611"/>
  </entry>
</feed>
