High · published April 8, 2026
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
| Product | Versions | Fixed in |
|---|---|---|
| golang/go | < 1.25.9 | 1.25.9 |
| golang/go | ≥ 1.26.0, < 1.26.2 | 1.26.2 |