GNUTLS RSA-PSK Username NUL Bypass Auth
CVE-2026-42010 Published on May 7, 2026
Gnutls: gnutls: authentication bypass via nul character in username
A flaw was found in gnutls. Servers configured with RSA-PSK (RivestShamirAdleman Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.
Vulnerability Analysis
CVE-2026-42010 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Types
Improper Null Termination
The software does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator. Null termination errors frequently occur in two different ways. An off-by-one error could cause a null to be written out of bounds, leading to an overflow. Or, a program could use a strncpy() function call incorrectly, which prevents a null terminator from being added at all. Other scenarios are possible.
What is a Poison Null Byte Vulnerability?
The product does not properly handle null bytes or NUL characters when passing data between different representations or components.
CVE-2026-42010 has been classified to as a Poison Null Byte vulnerability or weakness.
Products Associated with CVE-2026-42010
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42010 are published in these products:
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:3.8.10-4.el10_2 and below * is unaffected.
- Version 0:3.8.9-9.el10_0.19 and below * is unaffected.
- Version 0:3.6.16-8.el8_10.6 and below * is unaffected.
- Version 0:3.6.16-8.el8_10.6 and below * is unaffected.
- Version 0:3.8.10-4.el9_8 and below * is unaffected.
- Version 0:3.8.10-4.el9_8 and below * is unaffected.
- Version 0:3.8.3-6.el9_6.4 and below * is unaffected.
- Version 1782159791 and below * is unaffected.
- Version 1782166952 and below * is unaffected.
- Version 3.8.13-1.hum1 and below * is unaffected.
- Version 1781525684 and below * is unaffected.
- Version 1781525671 and below * is unaffected.
- Version 1781525693 and below * is unaffected.
- Version 1781525739 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.