CVE-2026-56862

Published: August 15, 2026Last modified: August 26, 2026

Description

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.14-r0)
25 LTSgoFixed (1.25.14-r0)
StreamgoFixed (1.26.7-r0)
Hardened Containers23 LTSgoFixed (1.25.14-r0)
25 LTSgoFixed (1.25.14-r0)
StreamgoFixed (1.26.7-r0)

References

ON THIS PAGE