VDB
CVE-2026-78662
CVE-2026-78662
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published September 2, 2026
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| golang.org/x/crypto | golang.org/x/crypto/ssh | 0 |
| chainguard | crossplane-provider-aws-autoscalingplans-fips | *, * |
| chainguard | victoriametrics-operator | *, * |
| chainguard | crossplane-provider-aws-amplify | *, * |
| chainguard | cloud-provider-azure-1.33 | *, * |
| chainguard | cert-manager-fips-1.19 | *, * |
| chainguard | kubernetes-csi-external-snapshotter-8.4 | *, *, * |
| chainguard | flux-notification-controller | 0, 0 |
| chainguard | crossplane-provider-aws-dms-fips | *, * |
| chainguard | tkn-fips | *, * |
| wolfi | temporal | *, *, * |
| chainguard | zitadel-4 | 0, 0 |
| chainguard | kueue-fips-0.16 | *, *, * |
| wolfi | crossplane-provider-aws-cloudwatchlogs | *, *, * |
| chainguard | eks-distro-fips-1.32 | *, * |
| chainguard | crossplane-provider-aws-iot | *, * |
| chainguard | azuredisk-csi-1.33 | *, * |
| chainguard | commercial-grafana-13.2 | 0 |
| chainguard | prometheus-geomys-fips-3.12 | *, *, * |
| chainguard | kgateway-2.4 | *, *, * |
…and 2598 more
Timeline
- Sep 2, 2026 Coalition ESS Score
- Sep 2, 2026 CVE Published
- Sep 3, 2026 EPSS Score
- Sep 3, 2026 CVE Updated
- Sep 4, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score