Impact
The flaw allows a client to send a TLS handshake containing multiple ECH outer extension references, a construct disallowed by RFC 9849. The crypto/tls library previously accepted such packets, causing the server process to allocate excessive memory as it attempted to process each reference. The result is a memory amplification that can lead to exhaustion of the application’s resources, potentially crashing or degrading the server. The weakness is an uncontrolled resource consumption flaw rather than a directly exploitable code execution path.
Affected Systems
Any Go runtime that includes the standard library package crypto/tls that has not yet been updated to a release containing the fix is vulnerable. All Go applications that rely on the default TLS implementation and have not been upgraded to a release containing the fix are at risk.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, but the nature of the defect – a crafted packet that triggers uncontrolled memory usage – makes it a high‑severity denial‑of‑service risk. With a CVSS score of 7.5, the vulnerability is classified as high severity. An attacker can send the malformed handshake over a remote network link; the server will dutifully accept the packet, attempt to process the repeated references, and allocate memory until the process is killed or the system runs out of resources. Because the flaw is enforced only after successful parsing of the TLS record, the attack vector is remote and requires the ability to speak TLS to the affected service.
OpenCVE Enrichment