Vulnerability Report: GO-2026-4870
- CVE-2026-32283
- Affects: crypto/tls
- Published: Apr 07, 2026
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Affected Packages
-
PathVersionsSymbols
-
before go1.25.9, from go1.26.0-0 before go1.26.2
Aliases
References
- https://go.dev/cl/763767
- https://go.dev/issue/78334
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://vuln.go.dev/ID/GO-2026-4870.json
Credits
- Jakub Ciolek - https://ciolek.dev/
Feedback
See anything missing or incorrect?
Suggest an edit to this report.