Skip to main content
Version: v1.1.x

CVE-2026-5260

CVE Details

Visit the official vulnerability details page for CVE-2026-5260 to learn more.

Initial Publication

05/26/2026

Last Update

06/01/2026

Third Party Dependency

gnutls

NIST CVE Summary

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVE Severity

8.2

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.5⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.