<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:29:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09660</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09660</link>
      <description>bdu:2026-09660</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09660</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42012</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42012</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: gnutls, Alpaquita:25: gnutls, Alpaquita:stream: gnutls&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42012</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0737 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</link>
      <description>certfr-2026-avi-0737</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</guid>
    </item>
    <item>
      <title>EUVD-2026-382047</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382047</link>
      <description>EUVD-2026-382047</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382047</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42012</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42012</link>
      <description>&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42012</guid>
    </item>
    <item>
      <title>GHSA-7hhj-8fwv-m5hc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hhj-8fwv-m5hc</link>
      <description>&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hhj-8fwv-m5hc</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42012 — Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42012</link>
      <description>msrc_CVE-2026-42012</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42012</guid>
    </item>
    <item>
      <title>OESA-2026-3118 — gnutls security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3118</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: gnutls&lt;/p&gt;
&lt;p&gt;GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: gnutls&lt;/p&gt;
&lt;p&gt;GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, and other required structures. The project strives to provide a secure communications back-end, simple to use and integrated with the rest of the base Linux libraries. A back-end designed to work and be secure out of the box, keeping the complexity of TLS and PKI out of application code.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.(CVE-2026-3832)&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.(CVE-2026-42012)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3118</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10691-1 — gnutls-3.8.13-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1</link>
      <description>&lt;p&gt;gnutls-3.8.13-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gnutls-3.8.13-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10691-1</guid>
    </item>
    <item>
      <title>RHSA-2026:13274 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13274</link>
      <description>&lt;p&gt;gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability gnutls: gnutls: Authentication Bypass via NUL Character in Username gnutls: gnutls: Security bypass due to incorrect name constraint handling gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13274</guid>
    </item>
    <item>
      <title>RLSA-2026:20612 — Important: gnutls security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:20612</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: gnutls&lt;/p&gt;
&lt;p&gt;The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library,
which implements cryptographic algorithms and protocols such as SSL, TLS, and
DTLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
* gnutls: Fix crashing on an underflow with a DTLS datagram
(CVE-2026-33845)
* gnutls: Fix RSA-PSK identity truncation (CVE-2026-42010)
* gnutls: Fix case-sensitivity of domain name comparison in name
constraints (CVE-2026-3833)
* gnutls: Fix intersecting empty name constraints (CVE-2026-42011)
* gnutls: Denial of Service via heap buffer overflow in DTLS handshake
fragment reassembly (CVE-2026-33846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: gnutls&lt;/p&gt;
&lt;p&gt;The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library,
which implements cryptographic algorithms and protocols such as SSL, TLS, and
DTLS.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gnutls: Fix qsort comparator in DTLS reassembly (CVE-2026-42009)
* gnutls: Fix crashing on an underflow with a DTLS datagram
(CVE-2026-33845)
* gnutls: Fix RSA-PSK identity truncation (CVE-2026-42010)
* gnutls: Fix case-sensitivity of domain name comparison in name
constraints (CVE-2026-3833)
* gnutls: Fix intersecting empty name constraints (CVE-2026-42011)
* gnutls: Denial of Service via heap buffer overflow in DTLS handshake
fragment reassembly (CVE-2026-33846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:20612</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21752-1 — Security update for gnutls</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1</link>
      <description>&lt;p&gt;Security update for gnutls&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gnutls&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21752-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42012</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42012</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28, Ubuntu:26.04:LTS: gnutls28&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: gnutls28, Ubuntu:Pro:18.04:LTS: gnutls28, Ubuntu:Pro:20.04:LTS: gnutls28, Ubuntu:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-preview:22.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:22.04:LTS: gnutls28, Ubuntu:24.04:LTS: gnutls28, Ubuntu:Pro:FIPS-updates:24.04:LTS: gnutls28, Ubuntu:25.10: gnutls28, Ubuntu:26.04:LTS: gnutls28&lt;/p&gt;
&lt;p&gt;A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42012</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1312 — GnuTLS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1312</guid>
    </item>
  </channel>
</rss>
