Vulnerability GO-2026-6090

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Limit handshake messages we are willing to accept post-handshake in crypto/tls
<1.25.13
<1.25.13

Summary

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Details

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Impacted packages

Timeline

Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
3 days ago
September 25, 2026 at 10:41 AM UTC