Vulnerability GO-2026-4870

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 months ago
April 07, 2026 at 10:53 PM UTC
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
<1.25.9
<1.25.9

Summary

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

Details

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.

This only affects TLS 1.3.

Impacted packages

Timeline

Published
5 months ago
April 07, 2026 at 10:53 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 10:56 AM UTC