Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrg3-gfjw-hm96

Опубликовано: 08 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Ссылки

EPSS

Процентиль: 47%
0.00621
Низкий

7.5 High

CVSS3

Дефекты

CWE-764
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
redhat
4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
nvd
4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

msrc
4 месяца назад

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

CVSS3: 7.5
debian
4 месяца назад

If one side of the TLS connection sends multiple key update messages p ...

EPSS

Процентиль: 47%
0.00621
Низкий

7.5 High

CVSS3

Дефекты

CWE-764
CWE-770