CVE-2026-56862
cAdvisor Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-56862 is a Denial of Service vulnerability in the Go standard library's crypto/tls package, caused by improper handling of TLS handshake messages such as KeyUpdate. A malicious client can repeatedly send KeyUpdate messages — even before a handshake is completed — forcing the server to perform computationally expensive key derivation operations indefinitely. Affected versions include Go crypto/tls prior to 1.25.13, 1.26.0–1.26.5, and 1.27.0-0 through 1.27.0-rc.2. It was published on August 13, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

Detalhes técnicos

The root cause is that KeyUpdate handshake messages in Go's crypto/tls implementation are unconditionally treated as state-advancing, regardless of whether the TLS handshake has been completed (CWE-770: Allocation of Resources Without Limits or Throttling; CWE-1050: Excessive Platform Resource Consumption within a Loop). An unauthenticated remote attacker can establish a TLS connection and flood the server with KeyUpdate messages, triggering repeated HKDF-based key derivation operations without any rate limiting or validation that a full handshake has occurred. No authentication or user interaction is required, and the attack is fully automatable over the network. The fix is tracked in Go issue #80528 and code change CL 804261 (GitHub Advisory, Red Hat Bugzilla).

Impacto

Successful exploitation results in a Denial of Service against any Go application using the crypto/tls package for TLS server functionality. The server's CPU resources are exhausted by continuous key derivation operations, degrading or completely disabling service availability. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue affecting any service built on vulnerable Go versions (GitHub Advisory).

Exploração

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is rated automatable by NVD SSVC, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.185% (Feedly data) to 0.568% (GitHub Advisory), placing it in a moderate percentile for near-term exploitation likelihood. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Etapas de exploração

  1. Reconnaissance: Identify internet-facing services built with vulnerable Go versions (prior to 1.25.13, 1.26.6, or 1.27.0-rc.3) that expose TLS endpoints, using tools like Shodan, Censys, or banner grabbing.
  2. Establish TLS connection: Initiate a TLS connection to the target server without completing the full handshake negotiation.
  3. Send repeated KeyUpdate messages: Continuously transmit KeyUpdate handshake messages to the server before or during the handshake phase, exploiting the lack of validation that a handshake has been completed.
  4. Resource exhaustion: The server processes each KeyUpdate message as state-advancing and performs a full HKDF key derivation operation for each, consuming CPU resources indefinitely.
  5. Denial of Service achieved: With sufficient message volume, the server's CPU is saturated, causing degraded response times or complete service unavailability for legitimate clients (GitHub Advisory, Red Hat Bugzilla).

Indicadores de compromisso

  • Network: Unusually high volume of TLS KeyUpdate handshake messages from a single or small set of source IPs; TLS connections that remain open without completing the handshake while generating sustained CPU load on the server.
  • System: Sustained high CPU utilization on Go-based TLS server processes without a corresponding increase in legitimate application traffic or request throughput.
  • Logs: Application or system logs showing repeated TLS handshake state transitions or key derivation events without corresponding completed handshake entries; connection logs showing long-lived TLS sessions with minimal data transfer.

Mitigação e soluções alternativas

Upgrade to a patched version of the Go standard library: Go 1.25.13, Go 1.26.6, or Go 1.27.0-rc.3 or later. Red Hat has issued errata for affected products: RHSA-2026:60304 (RHEL 9), RHSA-2026:60305 (RHEL 8), and RHSA-2026:60306 (RHEL 10). SUSE has released updates SUSE-SU-2026:3640-1, SUSE-SU-2026:3799-1, SUSE-SU-2026:3815-1, and SUSE-SU-2026:3830-1. As a temporary workaround, consider implementing network-level rate limiting on TLS connections or deploying a TLS-terminating proxy with connection throttling in front of vulnerable services (GitHub Advisory, Red Hat Bugzilla).

Reações da comunidade

The Go team disclosed the vulnerability via the golang-announce mailing list and published a fix through the standard Go release process. Red Hat triaged the issue at high severity and issued errata across RHEL 8, 9, and 10. The vulnerability was also discussed on the oss-security mailing list and picked up by Linux security news outlets including Pro-Linux.de and LinuxSecurity.com. Community reaction has been measured, consistent with a DoS-only vulnerability with no public exploit code (golang-announce, Red Hat Bugzilla).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado cAdvisor Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-56865HIGH8.4
  • cAdvisor logocAdvisor
  • azure-keyvault-controller
NãoSimAug 13, 2026
CVE-2026-56864HIGH7.5
  • cAdvisor logocAdvisor
  • filebeat-8.19-fips
NãoSimAug 13, 2026
CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • aws-ebs-csi-driver-1.63
NãoSimAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • cloud-provider-aws-fips-1.36
NãoSimAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-vpclattice-fips
NãoSimAug 13, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades