← Browse

CVE-2026-5260

Medium

Elevated severity or exploit probability.

CVSS base
8.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS — probability of exploitation (30 days)
0.9%
59.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-126
Published 2026-05-26 · modified 2026-09-03

Description

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

References

Official: NVD · CVE.org