VDB

CVE-2026-56862

CVE-2026-56862 PUBLISHED CVSS 7.5 HIGH

Reported by Go · Published August 13, 2026

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Go standard librarycrypto/tls0, 1.26.0-0, 1.27.0-0
chainguardgitness0
chainguardgo-slim-1.26*
chainguardcri-tools0
wolfitemporal0, 0, 0
chainguardloki-fips-3.40, 0
chainguardgendesk0
chainguardconftest0
chainguardvirt-operator-fips-1.60
wolfiterraform0, 0, 0
chainguardprometheus-beat-exporter-fips0, 0
chainguardcosign-fips-30
wolfisonobuoy0, 0, 0
wolfichisel0, 0, 0
chainguardargo-rollouts-fips0
wolfiaddon-resizer0, 0, 0
chainguardkcp-fips-0.310
chainguardimage-factory-fips0
chainguardcrossplane-provider-aws-redshiftserverless-fips0
chainguardrancher-2.140, 0

…and 2808 more

Timeline

  • Aug 13, 2026 CVE Published
  • Aug 14, 2026 CVE Updated
  • Aug 15, 2026 Coalition ESS Score
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 29, 2026 Distribution Patch
  • Aug 29, 2026 Security Advisory
  • Aug 29, 2026 Distribution Patch
  • Aug 29, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›