CVE-2026-32283: Golang Go

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Affected products

  • Golang Go: before 1.25.9 (fixed in 1.25.9); from 1.26.0, before 1.26.2 (fixed in 1.26.2)

Published 2026-04-08. Last modified 2026-09-18.