High severity7.5NVD Advisory· Published Apr 8, 2026· Updated Apr 16, 2026
CVE-2026-32283
CVE-2026-32283
Description
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- go.dev/cl/763767nvdPatch
- pkg.go.dev/vuln/GO-2026-4870nvdVendor Advisory
- go.dev/issue/78334nvdIssue Tracking
- groups.google.com/g/golang-announce/c/0uYbvbPZRWUnvdRelease NotesMailing List
News mentions
0No linked articles in our index yet.