JLSEC-2026-519

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-519.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-519.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-519
Upstream
Published
2026-05-26T14:17:50.003Z
Modified
2026-05-26T14:30:03.264386004Z
Summary
[none]
Details

An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a norenegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutlsdeinit function is called after detecting a handshake failure.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "published": "2020-09-04T15:15:10.803Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24659",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2020-24659",
            "modified": "2024-11-21T05:15:26.003Z",
            "database_specific": {
                "status": "Modified"
            },
            "id": "CVE-2020-24659",
            "imported": "2026-05-22T18:34:34.730Z"
        }
    ]
}
References

Affected packages

Julia / GnuTLS_jll

Package

Name
GnuTLS_jll
Purl
pkg:julia/GnuTLS_jll?uuid=0951126a-58fd-58f1-b5b3-b08c7c4a876d

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.1+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-519.json"