{"id":"GO-2026-6090","summary":"Limit handshake messages we are willing to accept post-handshake in crypto/tls","details":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.","aliases":["CVE-2026-56862"],"modified":"2026-08-17T10:41:56.147714825Z","published":"2026-08-13T21:43:54Z","related":["CGA-j6x6-9m4j-6xmr","RHSA-2026:54835","RHSA-2026:54836"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6090"},"references":[{"type":"REPORT","url":"https://go.dev/issue/80528"},{"type":"FIX","url":"https://go.dev/cl/804261"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"}],"affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.13"},{"introduced":"1.26.0-0"},{"fixed":"1.26.6"},{"introduced":"1.27.0-0"},{"fixed":"1.27.0-rc.3"}]}],"ecosystem_specific":{"imports":[{"path":"crypto/tls","symbols":["Conn.Handshake","Conn.HandshakeContext","Conn.Read","Conn.Write","Conn.readRecordOrCCS","Dial","DialWithDialer","Dialer.Dial","Dialer.DialContext","QUICConn.HandleData","QUICConn.Start"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6090.json"}}],"schema_version":"1.9.0","credits":[{"name":"Qi Deng of Aurascape.ai"}]}