Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42505

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

A flaw was found in the crypto/tls package in Go. Handshakes utilizing Encrypted Client Hello (ECH) could lead to de-anonymization by a passive network observer. This is due to the disclosure of pre-shared key identities within the unencrypted client hello, allowing an attacker to potentially link connections.

Отчет

This Moderate-impact information disclosure flaw in the Go crypto/tls package allows a passive network observer to de-anonymize connections utilizing Encrypted Client Hello (ECH). The vulnerability stems from the unintentional exposure of pre-shared key identities within the unencrypted client hello, potentially enabling an attacker to link previously anonymous connections. This primarily affects the privacy of communications rather than integrity or availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Under investigation
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Compliance Operatorcompliance/openshift-compliance-operator-bundleFix deferred
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Under investigation
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorFix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2498138crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello

EPSS

Процентиль: 33%
0.00413
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

CVSS3: 5.3
nvd
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

msrc
23 дня назад

Invoking Encrypted Client Hello privacy leak in crypto/tls

CVSS3: 5.3
debian
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by ...

CVSS3: 5.3
github
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

EPSS

Процентиль: 33%
0.00413
Низкий

5.3 Medium

CVSS3