Github.Com Refraction-Networking Utls vulnerabilities
3 known vulnerabilities affecting github.com/refraction-networking_utls.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2026-26994P3MEDIUM≥ 0, < 1.7.02025-04-23
CVE-2026-26994 [MEDIUM] CWE-693 uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
### Description
Before version 1.7.0, utls did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a utls ClientHello spec. This allowed an active network adversary to downgrade TLS 1.3 connections initiated by a utls client to a lower TLS version (e.g., TLS 1.2) b
ghsaosv
CVE-2026-27017P4LOW≥ 1.6.0, < 1.8.12026-02-18
CVE-2026-27017 [LOW] CWE-1240 uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
There is a fingerprint mismatch with Chrome when using GREASE ECH, having to do with ciphersuite selection. When Chrome selects the preferred ciphersuite in the outer ClientHello and the ciphersuite for ECH, it does so consistently based on hardware support. That means, for example, if it prefers AES for t
ghsaosv
CVE-2026-26995LOW≥ 1.6.0, < 1.8.22026-02-18
CVE-2026-26995 [LOW] CWE-200 uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
The padding extension was incorrectly removed in utls for the non-pq variant of Chrome 120 fingerprint. Chrome removed this extension only when sending pq keyshares. Only this fingerprint is affected since newer fingerprints have pq keyshares by default and older fingerprints have this extension.
Affec
ghsaosv