Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qch-w8m5-g3h3

Опубликовано: 14 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

EPSS

Процентиль: 45%
0.00568
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

CVSS3: 7.5
redhat
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

CVSS3: 7.5
nvd
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

msrc
16 дней назад

Limit handshake messages we are willing to accept post-handshake in crypto/tls

CVSS3: 7.5
debian
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state- ...

EPSS

Процентиль: 45%
0.00568
Низкий

7.5 High

CVSS3

Дефекты

CWE-770