CVE Tracker

CVE-2026-42010 @ Library

Status
not_applicable
Priority
3.36
Match score
3.0
Risk
AuthBypass Remote priv:user
CVSS
7.1 HIGH
Reason
cpe: gnutls; pkgs: gnutls-deb0-28, gnutls-openssl27; version: unknown (gnutls-deb0-28-3.3.8-6+deb8u7; gnutls-openssl27-3.5.8-5+deb9u6); risk:auth_bypass; remote
Created
2026-08-03T02:35:42Z
Updated
2026-08-22T10:15:30Z
Closed
2026-08-03T03:27:38Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
gnutls-deb0-28-3.3.8-6+deb8u7
gnutls-openssl27-3.5.8-5+deb9u6)
gnutls-deb0-28
gnutls

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: gnutls-deb0 · gnutls-openssl27 · gnutls · gnutls-deb0-28

SystemMatchesTicket for CVE-2026-42010
Library libcurl3-gnutls 7.52.1-5+deb9u16; libgnutls-deb0-28 3.3.8-6+deb8u7; libgnutls-openssl27 3.5.8-5+deb9u6; libgnutls30 3.5.8-5+deb9u6 not_applicable open
Matrix libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls-dane0 3.7.9-2+deb12u7; libgnutls30 3.7.9-2+deb12u7 not_applicable open
Saiph libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls-deb0-28 3.3.8-6+deb8u6; libgnutls-openssl27 3.6.7-4+deb10u12; libgnutls30 3.6.7-4+deb10u12 not_applicable open
morris gnutls 3.3.29 not_applicable open
mufasa gnutls 3.3.29 not_applicable open
Archive libgnutls30 3.6.7-4+deb10u12 none
Bullseye libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 none
Helios libcurl3-gnutls 7.74.0-1.3+deb11u16; libgnutls30 3.7.1-5+deb11u10 none
Janus libcurl3-gnutls 7.64.0-4+deb10u9; libgnutls30 3.6.7-4+deb10u12 none
Silk libcurl3-gnutls 7.88.1-10+deb12u15; libgnutls30 3.7.9-2+deb12u7 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-33845 7.5 Library, Saiph, morris, mufasa accepted_risk, does_not_affect gnutls
CVE-2026-1584 7.5 Library, Saiph, morris, mufasa new gnutls
CVE-2026-42009 7.5 Library, Matrix, Saiph, morris, mufasa not_applicable gnutls → CVE-2026-42010 linked here

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Other CVEs related to this one as primary:

Related CVENoteTickets
CVE-2026-42009 same product as CVE-2026-42010 morris, mufasa, Library, Matrix, Saiph

Host OS / kernel

OS
Debian GNU/Linux 9 (stretch) (9) · debian
Arch
x86_64
kernel_release
uname -r → 4.9.0-19-amd64
kernel_version
uname -v → #1 SMP Debian 4.9.320-2 (2022-06-30)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris not_applicable 7.71 2026-08-22T10:15:30Z Open
mufasa not_applicable 7.71 2026-08-22T10:15:30Z Open
Saiph not_applicable 2.43 2026-08-22T10:15:30Z Open
Matrix not_applicable 1.86 2026-08-03T17:04:51Z Open

Description

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Determination

CVE-2026-42010 is an authentication bypass in GnuTLS.

Practical Risk

This only affects systems that actually use RSA-PSK authentication with GnuTLS. If you are not using RSA-PSK, the practical impact is low, but the package itself remains vulnerable.
Quick Conclusion
Unless you (or an application you installed) have explicitly configured RSA-PSK authentication, you are very unlikely to be using it, and the practical risk of CVE-2026-42010 is low even though the library is technically vulnerable.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-03T03:23:58Z — reviewing
CVE-2026-42010 is an authentication bypass in GnuTLS. Practical Risk This only affects systems that actually use RSA-PSK authentication with GnuTLS. If you are not using RSA-PSK, the practical impact is low, but the package itself remains vulnerable.
2026-08-03T03:26:40Z
Practical Reality On a typical server (web hosting, mail, cPanel, etc.), RSA-PSK is almost never used. Most systems that have GnuTLS installed use it for normal certificate-based TLS (HTTPS, IMAPS, etc.), which is not affected by this CVE.
2026-08-03T03:27:38Z — not_applicable
Quick Conclusion Unless you (or an application you installed) have explicitly configured RSA-PSK authentication, you are very unlikely to be using it, and the practical risk of CVE-2026-42010 is low even though the library is technically vulnerable.

References

NVD: CVE-2026-42010