Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

GO-2026-4870 · BIT-golang-2026-32283 · CVE-2026-32283

Published · Modified

Description

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.

This only affects TLS 1.3.

Ready to move

Start Securing

Free, no credit card | First findings in minutes