We found results for “”
CVE-2026-1584
Good to know:
Date: February 9, 2026
In libgnutls 3.8.11 there is a NULL pointer dereference in PSK binder verification. A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server. The updated code guards against the problematic dereference. The issue is fixed in 3.8.12.
Severity Score
Severity Score
Weakness Type (CWE)
NULL Pointer Dereference
CWE-476Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


