BRIEFING NOTE: CVE-2026-32283 CVE-2026-32283 is a denial of service vulnerability in TLS 1.3 implementations that occurs when one side of a connection sends multiple key update messages post-handshake within a single record, causing the connection to deadlock and resulting in uncontrolled resource consumption. This vulnerability affects TLS 1.3 connections exclusively and can be exploited by remote, unauthenticated attackers without user interaction. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector, low complexity, and no privileges or user interaction required. The impact is limited to availability, as the attack exclusively causes denial of service through resource exhaustion without compromising confidentiality or integrity. The attack surface is broad given that any TLS 1.3 implementation vulnerable to this flaw can be targeted remotely. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.00017 indicates low probability of exploitation relative to other CVEs, and the vulnerability remains on the Hot List as inactive. No widespread exploit code availability has been reported, suggesting limited community attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.9CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.2CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.