CVE Database
/

CVE-2026-32283

Back to search

CVE-2026-32283

Published: Apr 8, 2026

Modified: Apr 13, 2026

PUBLISHED

Description

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

VendorProductVersions

Go standard library

crypto/tls

affected
0 - < 1.25.9
affected
1.26.0-0 - < 1.26.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now