CVE Tracker

CVE-2026-42010 @ Matrix

Status
not_applicable
Priority
1.86
Match score
3.0
Risk
AuthBypass Remote priv:user
CVSS
7.1 HIGH
Reason
cpe: gnutls; pkgs: gnutls-dane0; version: unknown (gnutls-dane0-3.7.9-2+deb12u7); risk:auth_bypass
Created
2026-08-03T02:35:42Z
Updated
2026-08-03T17:04:51Z
Closed
2026-08-03T03:27:38Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
gnutls-dane0-3.7.9-2+deb12u7)
gnutls

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: gnutls-dane0 · gnutls

SystemMatchesTicket for CVE-2026-42010
Matrix libgnutls-dane0 3.7.9-2+deb12u7 not_applicable open

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-33845 7.5 Library, Saiph, morris, mufasa accepted_risk, does_not_affect gnutls
CVE-2026-1584 7.5 Library, Saiph, morris, mufasa new gnutls
CVE-2026-42009 7.5 Library, Matrix, Saiph, morris, mufasa not_applicable gnutls → CVE-2026-42010 linked here

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Other CVEs related to this one as primary:

Related CVENoteTickets
CVE-2026-42009 same product as CVE-2026-42010 morris, mufasa, Library, Matrix, Saiph

Host OS / kernel

OS
Debian GNU/Linux 12 (bookworm) (12) · debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64
kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris not_applicable 7.71 2026-08-22T10:15:30Z Open
mufasa not_applicable 7.71 2026-08-22T10:15:30Z Open
Library not_applicable 3.36 2026-08-22T10:15:30Z Open
Saiph not_applicable 2.43 2026-08-22T10:15:30Z Open

Description

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.

Determination

CVE-2026-42010 is an authentication bypass in GnuTLS.

Practical Risk

This only affects systems that actually use RSA-PSK authentication with GnuTLS. If you are not using RSA-PSK, the practical impact is low, but the package itself remains vulnerable.
Quick Conclusion
Unless you (or an application you installed) have explicitly configured RSA-PSK authentication, you are very unlikely to be using it, and the practical risk of CVE-2026-42010 is low even though the library is technically vulnerable.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-03T03:23:58Z — reviewing
CVE-2026-42010 is an authentication bypass in GnuTLS. Practical Risk This only affects systems that actually use RSA-PSK authentication with GnuTLS. If you are not using RSA-PSK, the practical impact is low, but the package itself remains vulnerable.
2026-08-03T03:26:40Z
Practical Reality On a typical server (web hosting, mail, cPanel, etc.), RSA-PSK is almost never used. Most systems that have GnuTLS installed use it for normal certificate-based TLS (HTTPS, IMAPS, etc.), which is not affected by this CVE.
2026-08-03T03:27:38Z — not_applicable
Quick Conclusion Unless you (or an application you installed) have explicitly configured RSA-PSK authentication, you are very unlikely to be using it, and the practical risk of CVE-2026-42010 is low even though the library is technically vulnerable.

References

NVD: CVE-2026-42010