Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-11703

около 2 месяцев назад

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-11703

около 2 месяцев назад

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-11703

около 1 месяца назад

Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption

EPSS: Низкий
debian логотип

CVE-2026-11703

около 2 месяцев назад

Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q3px-vrjj-4f97

около 2 месяцев назад

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-11703

Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-q3px-vrjj-4f97

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally negotiated and, where client-authentication policy differs across virtual hosts, carry the cached peer-authentication state into a context it was not established for. Resumption now verifies the SNI/ALPN binding for all paths and declines (falling back to a full handshake) on mismatch.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу