August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-1584NVD

Vulnerability Summary

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Severity Level
HIGH(7.5)
Published Date
Apr 9, 2026
Last Modified
Jun 30, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
1.32%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh