Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56862

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

EPSS

Процентиль: 45%
0.00568
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

CVSS3: 7.5
redhat
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

msrc
16 дней назад

Limit handshake messages we are willing to accept post-handshake in crypto/tls

CVSS3: 7.5
debian
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state- ...

CVSS3: 7.5
github
23 дня назад

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

EPSS

Процентиль: 45%
0.00568
Низкий

7.5 High

CVSS3

Дефекты

CWE-770