CVE-2026-56862
published 2026-08-13CVE-2026-56862: Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
45.0th percentile
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
Affected
106 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| albo | aws-load-balancer-operator | — | — |
| albo | aws-load-balancer-rhel8-operator | — | — |
| ansible-automation-platform-26 | receptor-rhel9 | — | — |
| ansible-automation-platform-27 | receptor-rhel9 | — | — |
| ansible-automation-platform | platform-operator-bundle | — | — |
| apache | thrift | — | — |
| build-of-trustee | trustee-rhel9-operator | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-compliance-operator-bundle | — | — |
| compliance | openshift-selinuxd-rhel8 | — | — |
| confidential-containers | trustee | — | — |
| container-native-virtualization | kubemacpool-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | conmon | — | — |
| container-tools_rhel8 | containernetworking-plugins | — | — |
| container-tools_rhel8 | crun | — | — |
| container-tools_rhel8 | oci-seccomp-bpf-hook | — | — |
| container-tools_rhel8 | podman | — | — |
| container-tools_rhel8 | runc | — | — |
| container-tools_rhel8 | skopeo | — | — |
| container-tools_rhel8 | toolbox | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
vendor_redhat·2026-08-13·CVSS 7.5
CVE-2026-56862 [HIGH] CWE-1050 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
A flaw was found in the `crypto/tls` package, part of `golang`. A malicious client can exploit this vulnerability by continuously sending KeyUpdate messages to a server. This forces the server to perform indefinite key derivation operations, leading to resource exhaustion and a Denial of Service (DoS) condition.
Package: rhai/assisted-installer-rhel9 (Assisted Installer for Red Hat OpenShift Container Platform 2) - Affected
Package: albo/aws-load-balancer-operator (AWS Load Balancer Operator) - Affected
Package: albo/aws-load-balancer-rhel8-operator (AWS Load Balancer Operator) - Affected
Package: openshift-builds/openshift-builds-waiters-rhel9 (Builds for Red Hat OpenShift) - Affected
Package:
VulDB
Go crypto tls up to 1.25.12/1.26.5 Client allocation of resources
vuldb·2026-08-14
CVE-2026-56862 [LOW] Go crypto tls up to 1.25.12/1.26.5 Client allocation of resources
A vulnerability, which was classified as problematic, has been found in Go crypto tls up to 1.25.12/1.26.5. This impacts an unknown function of the component Client Handler. The manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-56862. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not.
ghsa_unreviewed·2026-08-14
CVE-2026-56862 Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not.
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
No detection rules found.
No public exploits indexed.
2026-08-13
Published