PT-2026-44579 · Gnu+1 · Gnutls+1

CVE-2026-10028

·

Published

2026-05-28

·

Updated

2026-07-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions glib-networking (affected versions not specified)
Description A flaw exists where a remote attacker can cause a denial of service for an affected process or worker. This occurs when an application uses glib-networking with the GnuTLS backend enabled and performs certificate verification. By presenting a specially crafted certificate chain containing circular issuer relationships, an attacker can trigger an infinite loop during the verification process. This unbounded traversal consumes excessive CPU resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10028
ECHO-F55E-6DD0-D4B5
OESA-2026-2561
OPENSUSE-SU-2026:11010-1
OPENSUSE-SU-2026:21130-1
SUSE-SU-2026:22102-1
SUSE-SU-2026:22135-1
SUSE-SU-2026:22230-1
SUSE-SU-2026:22297-1
SUSE-SU-2026:2810-1
SUSE-SU-2026:3032-1
SUSE-SU-2026:3121-1

Affected Products

Gnutls
Glib-Networking