Vulnerability GO-2026-6090
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Limit handshake messages we are willing to accept post-handshake in crypto/tls
<1.25.13
<1.25.13
Summary
Limit handshake messages we are willing to accept post-handshake in crypto/tls
Details
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
1 month ago
Enforce maximum recursion depth in encoding/asn1
<1.25.13 GO-2026-5972
<1.25.13 GO-2026-5972
Unknown
1 month ago
Add recursion depth guard during decode in encoding/xml
<1.25.13 GO-2026-6088
<1.25.13 GO-2026-6088
Unknown
1 month ago
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
<1.25.13 GO-2026-6089
<1.25.13 GO-2026-6089
Unknown
1 month ago
Fix Javascript regexp context tracking in html/template
<1.25.13 GO-2026-6091
<1.25.13 GO-2026-6091
Unknown
1 month ago
Avoid quadratic complexity in resolvePath in net/url
<1.25.13 GO-2026-6218
<1.25.13 GO-2026-6218
Impacted packages
Timeline
Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
3 days ago
September 25, 2026 at 10:41 AM UTC