CVE-2026-97031
Reject malformed ECH outer extension references in crypto/tls
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
| Vendor | go standard library |
| Product | crypto/tls |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for go standard library crypto/tls
Be the first to know when new unknown vulnerabilities affecting go standard library crypto/tls are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Go standard library / crypto/tls
0 < 1.26.9 1.27.0-0 < 1.27.2