VDB

CVE-2026-78662

CVE-2026-78662 PUBLISHED CVSS 7.5 HIGH

Reported by Go · Published September 2, 2026

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
golang.org/x/cryptogolang.org/x/crypto/ssh0
chainguardcrossplane-provider-aws-autoscalingplans-fips*, *
chainguardvictoriametrics-operator*, *
chainguardcrossplane-provider-aws-amplify*, *
chainguardcloud-provider-azure-1.33*, *
chainguardcert-manager-fips-1.19*, *
chainguardkubernetes-csi-external-snapshotter-8.4*, *, *
chainguardflux-notification-controller0, 0
chainguardcrossplane-provider-aws-dms-fips*, *
chainguardtkn-fips*, *
wolfitemporal*, *, *
chainguardzitadel-40, 0
chainguardkueue-fips-0.16*, *, *
wolficrossplane-provider-aws-cloudwatchlogs*, *, *
chainguardeks-distro-fips-1.32*, *
chainguardcrossplane-provider-aws-iot*, *
chainguardazuredisk-csi-1.33*, *
chainguardcommercial-grafana-13.20
chainguardprometheus-geomys-fips-3.12*, *, *
chainguardkgateway-2.4*, *, *

…and 2598 more

Timeline

  • Sep 2, 2026 Coalition ESS Score
  • Sep 2, 2026 CVE Published
  • Sep 3, 2026 EPSS Score
  • Sep 3, 2026 CVE Updated
  • Sep 4, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›