crypto/tls vulnerability

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Published 8 Apr 2026Updated 7 Sep 2026134 sources
CVSS 7.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.