CVE-2026-42010
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing
CVSS
7.1
High
EPSS
1.1%
p62
KEV
—
Exploit Today
19
0-100
Published: May 7, 2026 · Last modified: Sep 1, 2026 · CWE-170 · CWE-626
1.1%EPSS · 30 days1.1%
2026-08-042026-08-31
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13274
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20611
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20612
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20613
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:26319
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:26409
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:29197
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30004
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30849
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30850
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:32962
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33125
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34764
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34788
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34790
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36004
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36005
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36006
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:40762
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:41921
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-768163.5 LOW6.9%
——2Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers. The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.8dCVE-2026-623807.5 HIG16.5%
——5Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.5dCVE-2026-457987.5 HIG40.6%
——12Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The function is reachable before authentication through wazuh-authd on TCP port 1515 when anonymous TLS enrollment is enabled. A version string of at least nine non-null bytes can cause strchr() and strtok() to read beyond ver2 and can make strtok() write a null byte into adjacent stack memory, allowing a remote denial of service. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.13dCVE-2026-444525.9 MED34.3%
——10h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy the hostname, assuming that it is NULL-terminated. This is a potential denial-of-service attack vector in sense that it might trigger segmentation violation. This issue has been fixed by commit 8dc37cb.27dCVE-2026-123863.9 LOW3.2%
——1Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Overflow Buffers.
This issue affects Pardus Pen: from <=4.1.5 before 4.2.1.57dCVE-2026-557388.8 HIG32.9%
——10A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.23d