crypto/tls vulnerability

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Published 8 Apr 2026Updated 7 Sep 2026134 sources
CVSS 7.5

Source timeline

CVE record published by NVDView source ↗