PatchDay Alert

CVE

CVE-2026-42010

0field notes · 1digest CVSS 7.1


Daily digests

GnuTLS mishandles a NUL character in usernames during authentication, allowing an attacker to bypass authentication entirely. If your services rely on GnuTLS for TLS client certificate or SRP authentication, someone could slip past identity checks with a crafted username. CVSS 7.1, not yet exploited in the wild.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.