CVE-2026-26995: 
vulnerability analysis and mitigation

Overview

CVE-2026-26995 is a fingerprint vulnerability in the uTLS Go library caused by a missing padding extension in the Chrome 120 TLS fingerprint implementation. It affects github.com/refraction-networking/utls versions >= 1.6.0 and < 1.8.2. The CVE has been formally rejected by the CVE Program, with the determination that the issue is an external dependency vulnerability rather than a flaw in uTLS itself. It carries a CVSS v4 base score of 2.3 (Low) (Github Advisory).

Technical details

The root cause (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) is that the padding extension was incorrectly removed from the HelloChrome_120 TLS fingerprint profile in uTLS. Chrome only removes this extension when sending post-quantum (PQ) keyshares, but the non-PQ variant of the Chrome 120 fingerprint in uTLS omitted it unconditionally. This discrepancy causes the TLS ClientHello generated by uTLS to deviate from a genuine Chrome 120 fingerprint, potentially allowing a passive network observer to distinguish uTLS-based traffic from real Chrome traffic. Only the HelloChrome_120 symbol is affected; newer fingerprints include PQ keyshares by default and older fingerprints retain the extension (Github Advisory).

Impact

The primary impact is a low-severity confidentiality exposure: a passive network observer could fingerprint TLS connections made using the HelloChrome_120 profile and identify them as not originating from a genuine Chrome 120 browser, potentially de-anonymizing or detecting tools (e.g., censorship circumvention proxies) that rely on uTLS for browser impersonation. There is no integrity or availability impact, and no subsequent system impact is expected (Github Advisory).

Exploitability

No public exploit code, active in-the-wild exploitation, or threat actor attribution has been reported for this vulnerability. The CVE has been formally rejected, and the GHSA advisory notes zero Dependabot alerts. The attack requires network-level passive observation and user interaction (passive), with high attack complexity, making opportunistic exploitation unlikely. No EPSS score or CISA KEV listing is associated with this CVE (Github Advisory).

Mitigation and workarounds

The fix is available in github.com/refraction-networking/utls version 1.8.2, which restores the padding extension to the HelloChrome_120 non-PQ fingerprint profile (fix commit: 8fe0b08e9a0e7e2d08b268f451f2c79962e6acd0). Developers using affected versions (>= 1.6.0, < 1.8.2) should upgrade their Go module dependency to 1.8.2 or later. No configuration-based workaround is available; upgrading is the only remediation (Github Advisory).

Community reactions

The vulnerability was reported by Telegram user @acgdaily and disclosed by maintainer ewust on February 17, 2026. The CVE was subsequently rejected by the CVE Program on the basis that the issue stems from an external dependency rather than a core uTLS defect. Community reaction has been minimal given the low severity and narrow impact scope (Github Advisory).

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management