PT-2026-47001 · Julia · Gnutls Jll

Published

2026-05-26

·

Updated

2026-05-26

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls deinit function is called after detecting a handshake failure.

Related Identifiers

JLSEC-2026-519

Affected Products

Gnutls Jll