Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrg3-gfjw-hm96

Опубликовано: 08 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

EPSS

Процентиль: 36%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
redhat
3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
nvd
3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

msrc
2 месяца назад

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

CVSS3: 7.5
debian
3 месяца назад

If one side of the TLS connection sends multiple key update messages p ...

EPSS

Процентиль: 36%
0.00449
Низкий

7.5 High

CVSS3

Дефекты

CWE-770