Skip to main content
EPSS 1.1%top 38%

CVE-2026-42010: Improper Null Termination

0
High
Published: 05/07/2026 (05/07/2026, 12:00:05 UTC)
Source: GCVE Database

Description

CVE-2026-42010 is a vulnerability in GnuTLS affecting servers configured with RSA-PSK authentication. The flaw involves improper handling of usernames containing a null (NUL) character, causing the server to match truncated usernames incorrectly. This can be exploited remotely by sending a specially crafted username to bypass authentication and gain unauthorized access. The vulnerability has a CVSS score of 7.1, indicating high severity. Red Hat has released security updates addressing this issue in GnuTLS packages for various Red Hat products, including Red Hat Enterprise Linux 8 and Red Hat Hardened Images. Users are advised to apply these updates to mitigate the risk.

CVSS v3.1

Score 7.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected software

redhat/openshift-container-platform
pkg:rpm/redhat/openshift-container-platform
Affected versions
<4.22.4 >=4.22

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 15:02:54 UTC

Technical Analysis

The vulnerability CVE-2026-42010 in GnuTLS arises from improper null termination handling in RSA-PSK username matching. Specifically, servers configured with RSA-PSK authentication incorrectly match usernames containing a NUL character with truncated usernames, enabling an attacker to bypass authentication by sending a crafted username. This flaw allows unauthorized access by circumventing the authentication process. Red Hat has issued security advisories and updates for affected GnuTLS packages, including versions >=4.22.0 and <4.22.4, and for Red Hat Enterprise Linux 8 packages such as gnutls-3.6.16-8.el8_10.6. The updates fix the authentication bypass and other related security issues. The CVSS v3.1 base score is 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), reflecting a high severity impact primarily on confidentiality.

Potential Impact

An attacker can exploit this vulnerability to bypass authentication on servers using GnuTLS with RSA-PSK, gaining unauthorized access. The impact is high confidentiality loss with limited integrity impact and no availability impact. This can lead to unauthorized access to protected resources or services relying on GnuTLS authentication.

Mitigation Recommendations

Red Hat has released official security updates that fix this vulnerability. Users should apply the updated GnuTLS packages provided in Red Hat advisories RHSA-2026:13274 and RHSA-2026:20611. The updates include gnutls-3.8.13-1.hum1 for Red Hat Hardened Images and gnutls-3.6.16-8.el8_10.6 for Red Hat Enterprise Linux 8. Applying these updates mitigates the authentication bypass issue. No additional mitigation steps are required beyond applying the vendor-provided patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:34790
Cve Count
1
State
PUBLISHED

Threat ID: 6a55ffc368715ace432fccde

Added to database: 07/14/2026, 09:22:11 UTC

Last enriched: 09/12/2026, 15:02:54 UTC

Last updated: 09/15/2026, 00:23:06 UTC

Views: 159

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses