Medium severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102759
CVE-2026-102759
Description
NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In _nx_secure_verify_mac, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.
Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.