CVE-2026-97031: Go Standard Library Crypto/tls

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.

Affected products

  • Go Standard Library Crypto/tls: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)

Published 2026-10-08. Last modified 2026-10-09.