crypto/tls vulnerability

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Published 8 Jul 2026Updated 16 Sep 20264 sources
CVSS 5.3

What happened

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Affected versions

crypto/tls: before 1.25.12 (semver); 1.26.0-0 through before 1.26.5 (semver); 1.27.0-0 through before 1.27.0-rc.2 (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.