Description
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Published: 2026-04-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Go TLS 1.3 implementation incorrectly processes a batch of key update messages sent in a single record after the handshake. When such duplicate key updates are received, the connection can deadlock, leading to uncontrolled consumption of system resources and a denial of service. This vulnerability can be triggered by an attacker sending a crafted TLS session that includes multiple key update records.

Affected Systems

The vulnerability affects the Go standard library package crypto/tls and therefore any Go application that enables TLS 1.3 handling through this library. The issue is present in all versions of Go that use the affected TLS implementation, regardless of vendor or product beyond the Go runtime. No specific product naming beyond Go’s standard library is required for the impact assessment.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is classified as high severity, while the EPSS score of less than 1% indicates a low likelihood of being actively exploited at the present time. The attacker only needs to supply a malformed TLS session and does not require any special privileges or prior access. The vulnerability is remote and does not require authentication to impact the system. Although it is not listed in the CISA Known Exploited Vulnerabilities catalog, it poses a significant risk if an undetected attacker can trigger the deadlock on a high‑traffic service. The recommended mitigations focus on applying the vendor patch or disabling TLS 1.3 until a fix is available.

Generated by OpenCVE AI on August 14, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Go runtime to the latest stable release that contains the fix for the TLS 1.3 key update handling bug
  • If an immediate upgrade is not possible, configure your Go applications to disable TLS 1.3 or enforce strict key update limits until the patch is available
  • Verify that your TLS configuration only accepts a single key update per record and monitor server logs for repeated key update messages to detect potential attempts to trigger the deadlock

Generated by OpenCVE AI on August 14, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10217 cve-icon
https://access.redhat.com/errata/RHSA-2026:10219 cve-icon
https://access.redhat.com/errata/RHSA-2026:10704 cve-icon
https://access.redhat.com/errata/RHSA-2026:11507 cve-icon
https://access.redhat.com/errata/RHSA-2026:11514 cve-icon
https://access.redhat.com/errata/RHSA-2026:11704 cve-icon
https://access.redhat.com/errata/RHSA-2026:11711 cve-icon
https://access.redhat.com/errata/RHSA-2026:11712 cve-icon
https://access.redhat.com/errata/RHSA-2026:11863 cve-icon
https://access.redhat.com/errata/RHSA-2026:11881 cve-icon
https://access.redhat.com/errata/RHSA-2026:14162 cve-icon
https://access.redhat.com/errata/RHSA-2026:14200 cve-icon
https://access.redhat.com/errata/RHSA-2026:14391 cve-icon
https://access.redhat.com/errata/RHSA-2026:15980 cve-icon
https://access.redhat.com/errata/RHSA-2026:16021 cve-icon
https://access.redhat.com/errata/RHSA-2026:16024 cve-icon
https://access.redhat.com/errata/RHSA-2026:16101 cve-icon
https://access.redhat.com/errata/RHSA-2026:16102 cve-icon
https://access.redhat.com/errata/RHSA-2026:16875 cve-icon
https://access.redhat.com/errata/RHSA-2026:17075 cve-icon
https://access.redhat.com/errata/RHSA-2026:17084 cve-icon
https://access.redhat.com/errata/RHSA-2026:17287 cve-icon
https://access.redhat.com/errata/RHSA-2026:18027 cve-icon
https://access.redhat.com/errata/RHSA-2026:18032 cve-icon
https://access.redhat.com/errata/RHSA-2026:19126 cve-icon
https://access.redhat.com/errata/RHSA-2026:19132 cve-icon
https://access.redhat.com/errata/RHSA-2026:19133 cve-icon
https://access.redhat.com/errata/RHSA-2026:19134 cve-icon
https://access.redhat.com/errata/RHSA-2026:19135 cve-icon
https://access.redhat.com/errata/RHSA-2026:19136 cve-icon
https://access.redhat.com/errata/RHSA-2026:19137 cve-icon
https://access.redhat.com/errata/RHSA-2026:19139 cve-icon
https://access.redhat.com/errata/RHSA-2026:19144 cve-icon
https://access.redhat.com/errata/RHSA-2026:19156 cve-icon
https://access.redhat.com/errata/RHSA-2026:19350 cve-icon
https://access.redhat.com/errata/RHSA-2026:19351 cve-icon
https://access.redhat.com/errata/RHSA-2026:19352 cve-icon
https://access.redhat.com/errata/RHSA-2026:19353 cve-icon
https://access.redhat.com/errata/RHSA-2026:19369 cve-icon
https://access.redhat.com/errata/RHSA-2026:19450 cve-icon
https://access.redhat.com/errata/RHSA-2026:19550 cve-icon
https://access.redhat.com/errata/RHSA-2026:19634 cve-icon
https://access.redhat.com/errata/RHSA-2026:19714 cve-icon
https://access.redhat.com/errata/RHSA-2026:19715 cve-icon
https://access.redhat.com/errata/RHSA-2026:19719 cve-icon
https://access.redhat.com/errata/RHSA-2026:19720 cve-icon
https://access.redhat.com/errata/RHSA-2026:19721 cve-icon
https://access.redhat.com/errata/RHSA-2026:19722 cve-icon
https://access.redhat.com/errata/RHSA-2026:19750 cve-icon
https://access.redhat.com/errata/RHSA-2026:19839 cve-icon
https://access.redhat.com/errata/RHSA-2026:20556 cve-icon
https://access.redhat.com/errata/RHSA-2026:20569 cve-icon
https://access.redhat.com/errata/RHSA-2026:20570 cve-icon
https://access.redhat.com/errata/RHSA-2026:20571 cve-icon
https://access.redhat.com/errata/RHSA-2026:20607 cve-icon
https://access.redhat.com/errata/RHSA-2026:20608 cve-icon
https://access.redhat.com/errata/RHSA-2026:20609 cve-icon
https://access.redhat.com/errata/RHSA-2026:21769 cve-icon
https://access.redhat.com/errata/RHSA-2026:22347 cve-icon
https://access.redhat.com/errata/RHSA-2026:22423 cve-icon
https://access.redhat.com/errata/RHSA-2026:22450 cve-icon
https://access.redhat.com/errata/RHSA-2026:22485 cve-icon
https://access.redhat.com/errata/RHSA-2026:22709 cve-icon
https://access.redhat.com/errata/RHSA-2026:22713 cve-icon
https://access.redhat.com/errata/RHSA-2026:22714 cve-icon
https://access.redhat.com/errata/RHSA-2026:22937 cve-icon
https://access.redhat.com/errata/RHSA-2026:23102 cve-icon
https://access.redhat.com/errata/RHSA-2026:23103 cve-icon
https://access.redhat.com/errata/RHSA-2026:23228 cve-icon
https://access.redhat.com/errata/RHSA-2026:23345 cve-icon
https://access.redhat.com/errata/RHSA-2026:24337 cve-icon
https://access.redhat.com/errata/RHSA-2026:24470 cve-icon
https://access.redhat.com/errata/RHSA-2026:24761 cve-icon
https://access.redhat.com/errata/RHSA-2026:24762 cve-icon
https://access.redhat.com/errata/RHSA-2026:25248 cve-icon
https://access.redhat.com/errata/RHSA-2026:25250 cve-icon
https://access.redhat.com/errata/RHSA-2026:25251 cve-icon
https://access.redhat.com/errata/RHSA-2026:25252 cve-icon
https://access.redhat.com/errata/RHSA-2026:26447 cve-icon
https://access.redhat.com/errata/RHSA-2026:26571 cve-icon
https://access.redhat.com/errata/RHSA-2026:26636 cve-icon
https://access.redhat.com/errata/RHSA-2026:27076 cve-icon
https://access.redhat.com/errata/RHSA-2026:28038 cve-icon
https://access.redhat.com/errata/RHSA-2026:28047 cve-icon
https://access.redhat.com/errata/RHSA-2026:28074 cve-icon
https://access.redhat.com/errata/RHSA-2026:29035 cve-icon
https://access.redhat.com/errata/RHSA-2026:29195 cve-icon
https://access.redhat.com/errata/RHSA-2026:29455 cve-icon
https://access.redhat.com/errata/RHSA-2026:29703 cve-icon
https://access.redhat.com/errata/RHSA-2026:33722 cve-icon
https://access.redhat.com/errata/RHSA-2026:34192 cve-icon
https://access.redhat.com/errata/RHSA-2026:34196 cve-icon
https://access.redhat.com/errata/RHSA-2026:34197 cve-icon
https://access.redhat.com/errata/RHSA-2026:34365 cve-icon
https://access.redhat.com/errata/RHSA-2026:36796 cve-icon
https://access.redhat.com/errata/RHSA-2026:39810 cve-icon
https://access.redhat.com/errata/RHSA-2026:41019 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:42644 cve-icon
https://access.redhat.com/errata/RHSA-2026:47712 cve-icon
https://access.redhat.com/errata/RHSA-2026:47714 cve-icon
https://access.redhat.com/errata/RHSA-2026:47716 cve-icon
https://access.redhat.com/errata/RHSA-2026:47719 cve-icon
https://access.redhat.com/errata/RHSA-2026:47721 cve-icon
https://access.redhat.com/errata/RHSA-2026:47722 cve-icon
https://access.redhat.com/errata/RHSA-2026:47910 cve-icon
https://access.redhat.com/errata/RHSA-2026:48036 cve-icon
https://access.redhat.com/errata/RHSA-2026:48790 cve-icon
https://access.redhat.com/errata/RHSA-2026:49509 cve-icon
https://access.redhat.com/errata/RHSA-2026:49600 cve-icon
https://access.redhat.com/errata/RHSA-2026:49944 cve-icon
https://access.redhat.com/errata/RHSA-2026:51288 cve-icon
https://access.redhat.com/errata/RHSA-2026:54191 cve-icon
https://access.redhat.com/errata/RHSA-2026:54435 cve-icon
https://access.redhat.com/errata/RHSA-2026:54757 cve-icon
https://access.redhat.com/errata/RHSA-2026:55898 cve-icon
https://access.redhat.com/errata/RHSA-2026:55900 cve-icon
https://access.redhat.com/errata/RHSA-2026:55901 cve-icon
https://access.redhat.com/errata/RHSA-2026:55902 cve-icon
https://access.redhat.com/errata/RHSA-2026:55903 cve-icon
https://access.redhat.com/errata/RHSA-2026:7291 cve-icon
https://access.redhat.com/errata/RHSA-2026:7385 cve-icon
https://access.redhat.com/security/cve/CVE-2026-32283 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2456338 cve-icon
https://go.dev/cl/763767 cve-icon cve-icon
https://go.dev/issue/78334 cve-icon cve-icon
https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU cve-icon cve-icon
https://pkg.go.dev/vuln/GO-2026-4870 cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json cve-icon
History

Thu, 20 Aug 2026 13:30:00 +0000


Tue, 18 Aug 2026 12:30:00 +0000


Fri, 14 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
References

Thu, 16 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang go
CPEs cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Vendors & Products Golang
Golang go

Tue, 14 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library crypto Tls
Vendors & Products Go Standard Library
Go Standard Library crypto Tls

Wed, 08 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
Description If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Title Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
References

Subscriptions

Go Standard Library Crypto Tls
Golang Go
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-08-21T12:12:54.490Z

Reserved: 2026-03-11T16:38:46.556Z

Link: CVE-2026-32283

cve-icon Vulnrichment

Updated: 2026-08-21T12:12:54.490Z

cve-icon NVD

Status : Modified

Published: 2026-04-08T02:16:03.580

Modified: 2026-08-20T13:17:32.257

Link: CVE-2026-32283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T04:15:03Z

Weaknesses
  • CWE-764

    Multiple Locks of a Critical Resource

  • CWE-770

    Allocation of Resources Without Limits or Throttling