PT-2026-5356 · Unknown · Trusttunnel

·

CVE-2026-24904

·

Publicado

2026-01-29

·

Atualizado

2026-01-29

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TrustTunnel versions prior to 0.9.115
Description TrustTunnel, an open-source VPN protocol, has a rule bypass issue. The issue resides in the interaction between tls listener.rs and rules.rs. Specifically, the TlsListener::listen() function peeks 1024 bytes and calls extract client random(...). If parsing of the TLS plaintext fails, extract client random returns None. The RulesEngine::evaluate function only evaluates client random prefix when client random is Some(...). Consequently, when extraction fails, rules relying on client random prefix are bypassed, and evaluation proceeds to subsequent rules. The client random prefix is a match condition and does not block non-matching prefixes.
Recommendations Update to TrustTunnel version 0.9.115 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24904
GHSA-FQH7-R5GF-3R87

Produtos afetados

Trusttunnel