VYPR

s2n-tls

by AWS

CVEs (2)

  • CVE-2026-16318Jul 21, 2026
    risk 0.00cvss epss 0.00

    The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second…

  • CVE-2026-16317Jul 21, 2026
    risk 0.00cvss epss 0.00

    Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer…