CVE-2026-56862
Go 脆弱性の分析と軽減

概要

CVE-2026-56862 is a Denial of Service vulnerability in the Go standard library's crypto/tls package, caused by improper handling of TLS handshake messages such as KeyUpdate. A malicious client can repeatedly send KeyUpdate messages — even before a handshake is completed — forcing the server to perform computationally expensive key derivation operations indefinitely. Affected versions include Go crypto/tls prior to 1.25.13, 1.26.0–1.26.5, and 1.27.0-0 through 1.27.0-rc.2. It was published on August 13, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

技術的な詳細

The root cause is that KeyUpdate handshake messages in Go's crypto/tls implementation are unconditionally treated as state-advancing, regardless of whether the TLS handshake has been completed (CWE-770: Allocation of Resources Without Limits or Throttling; CWE-1050: Excessive Platform Resource Consumption within a Loop). An unauthenticated remote attacker can establish a TLS connection and flood the server with KeyUpdate messages, triggering repeated HKDF-based key derivation operations without any rate limiting or validation that a full handshake has occurred. No authentication or user interaction is required, and the attack is fully automatable over the network. The fix is tracked in Go issue #80528 and code change CL 804261 (GitHub Advisory, Red Hat Bugzilla).

影響

Successful exploitation results in a Denial of Service against any Go application using the crypto/tls package for TLS server functionality. The server's CPU resources are exhausted by continuous key derivation operations, degrading or completely disabling service availability. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue affecting any service built on vulnerable Go versions (GitHub Advisory).

エクスプロイト可能性

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is rated automatable by NVD SSVC, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.185% (Feedly data) to 0.568% (GitHub Advisory), placing it in a moderate percentile for near-term exploitation likelihood. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing services built with vulnerable Go versions (prior to 1.25.13, 1.26.6, or 1.27.0-rc.3) that expose TLS endpoints, using tools like Shodan, Censys, or banner grabbing.
  2. Establish TLS connection: Initiate a TLS connection to the target server without completing the full handshake negotiation.
  3. Send repeated KeyUpdate messages: Continuously transmit KeyUpdate handshake messages to the server before or during the handshake phase, exploiting the lack of validation that a handshake has been completed.
  4. Resource exhaustion: The server processes each KeyUpdate message as state-advancing and performs a full HKDF key derivation operation for each, consuming CPU resources indefinitely.
  5. Denial of Service achieved: With sufficient message volume, the server's CPU is saturated, causing degraded response times or complete service unavailability for legitimate clients (GitHub Advisory, Red Hat Bugzilla).

妥協の兆候

  • Network: Unusually high volume of TLS KeyUpdate handshake messages from a single or small set of source IPs; TLS connections that remain open without completing the handshake while generating sustained CPU load on the server.
  • System: Sustained high CPU utilization on Go-based TLS server processes without a corresponding increase in legitimate application traffic or request throughput.
  • Logs: Application or system logs showing repeated TLS handshake state transitions or key derivation events without corresponding completed handshake entries; connection logs showing long-lived TLS sessions with minimal data transfer.

軽減策と回避策

Upgrade to a patched version of the Go standard library: Go 1.25.13, Go 1.26.6, or Go 1.27.0-rc.3 or later. Red Hat has issued errata for affected products: RHSA-2026:60304 (RHEL 9), RHSA-2026:60305 (RHEL 8), and RHSA-2026:60306 (RHEL 10). SUSE has released updates SUSE-SU-2026:3640-1, SUSE-SU-2026:3799-1, SUSE-SU-2026:3815-1, and SUSE-SU-2026:3830-1. As a temporary workaround, consider implementing network-level rate limiting on TLS connections or deploying a TLS-terminating proxy with connection throttling in front of vulnerable services (GitHub Advisory, Red Hat Bugzilla).

コミュニティの反応

The Go team disclosed the vulnerability via the golang-announce mailing list and published a fix through the standard Go release process. Red Hat triaged the issue at high severity and issued errata across RHEL 8, 9, and 10. The vulnerability was also discussed on the oss-security mailing list and picked up by Linux security news outlets including Pro-Linux.de and LinuxSecurity.com. Community reaction has been measured, consistent with a DoS-only vulnerability with no public exploit code (golang-announce, Red Hat Bugzilla).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 Go 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-56865HIGH8.4
  • Go logoGo
  • docker-machine-driver-linode
いいえはいAug 13, 2026
CVE-2026-56864HIGH7.5
  • Go logoGo
  • azure-ipam-fips
いいえはいAug 13, 2026
CVE-2026-56862HIGH7.5
  • Go logoGo
  • sops-fips
いいえはいAug 13, 2026
CVE-2026-56859HIGH7.5
  • Go logoGo
  • eks-distro-fips-1.36
いいえはいAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • Go logoGo
  • elastic-otel-collector-9.5
いいえはいAug 13, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者