Description
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Memory exhaustion leading to denial of service
Action: Update Go
AI Analysis

Impact

The flaw allows a client to send a TLS handshake containing multiple ECH outer extension references, a construct disallowed by RFC 9849. The crypto/tls library previously accepted such packets, causing the server process to allocate excessive memory as it attempted to process each reference. The result is a memory amplification that can lead to exhaustion of the application’s resources, potentially crashing or degrading the server. The weakness is an uncontrolled resource consumption flaw rather than a directly exploitable code execution path.

Affected Systems

Any Go runtime that includes the standard library package crypto/tls that has not yet been updated to a release containing the fix is vulnerable. All Go applications that rely on the default TLS implementation and have not been upgraded to a release containing the fix are at risk.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the nature of the defect – a crafted packet that triggers uncontrolled memory usage – makes it a high‑severity denial‑of‑service risk. With a CVSS score of 7.5, the vulnerability is classified as high severity. An attacker can send the malformed handshake over a remote network link; the server will dutifully accept the packet, attempt to process the repeated references, and allocate memory until the process is killed or the system runs out of resources. Because the flaw is enforced only after successful parsing of the TLS record, the attack vector is remote and requires the ability to speak TLS to the affected service.

Generated by OpenCVE AI on October 9, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Go release that implements the RFC 9849 compliance fix for crypto/tls (e.g., Go 1.22 or later).
  • Rebuild all Go applications that depend on the standard TLS library to ensure they link against the updated code.
  • Deploy network filtering or application‑level checks that drop TLS handshakes containing malformed ECH outer extensions as an interim protection until the library update is completed.

Generated by OpenCVE AI on October 9, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 09 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library crypto Tls
Vendors & Products Go Standard Library
Go Standard Library crypto Tls

Fri, 09 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Title Reject malformed ECH outer extension references in crypto/tls
References

Subscriptions

Go Standard Library Crypto Tls
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:58.775Z

Reserved: 2026-09-23T23:03:36.988Z

Link: CVE-2026-97031

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:06.037

Modified: 2026-10-08T23:17:06.037

Link: CVE-2026-97031

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-08T22:53:58Z

Links: CVE-2026-97031 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T02:15:20Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling