
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26995 is a fingerprint vulnerability in the uTLS Go library caused by a missing padding extension in the Chrome 120 TLS fingerprint implementation. It affects github.com/refraction-networking/utls versions >= 1.6.0 and < 1.8.2. The CVE has been formally rejected by the CVE Program, with the determination that the issue is an external dependency vulnerability rather than a flaw in uTLS itself. It carries a CVSS v4 base score of 2.3 (Low) (Github Advisory).
The root cause (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) is that the padding extension was incorrectly removed from the HelloChrome_120 TLS fingerprint profile in uTLS. Chrome only removes this extension when sending post-quantum (PQ) keyshares, but the non-PQ variant of the Chrome 120 fingerprint in uTLS omitted it unconditionally. This discrepancy causes the TLS ClientHello generated by uTLS to deviate from a genuine Chrome 120 fingerprint, potentially allowing a passive network observer to distinguish uTLS-based traffic from real Chrome traffic. Only the HelloChrome_120 symbol is affected; newer fingerprints include PQ keyshares by default and older fingerprints retain the extension (Github Advisory).
The primary impact is a low-severity confidentiality exposure: a passive network observer could fingerprint TLS connections made using the HelloChrome_120 profile and identify them as not originating from a genuine Chrome 120 browser, potentially de-anonymizing or detecting tools (e.g., censorship circumvention proxies) that rely on uTLS for browser impersonation. There is no integrity or availability impact, and no subsequent system impact is expected (Github Advisory).
No public exploit code, active in-the-wild exploitation, or threat actor attribution has been reported for this vulnerability. The CVE has been formally rejected, and the GHSA advisory notes zero Dependabot alerts. The attack requires network-level passive observation and user interaction (passive), with high attack complexity, making opportunistic exploitation unlikely. No EPSS score or CISA KEV listing is associated with this CVE (Github Advisory).
The fix is available in github.com/refraction-networking/utls version 1.8.2, which restores the padding extension to the HelloChrome_120 non-PQ fingerprint profile (fix commit: 8fe0b08e9a0e7e2d08b268f451f2c79962e6acd0). Developers using affected versions (>= 1.6.0, < 1.8.2) should upgrade their Go module dependency to 1.8.2 or later. No configuration-based workaround is available; upgrading is the only remediation (Github Advisory).
The vulnerability was reported by Telegram user @acgdaily and disclosed by maintainer ewust on February 17, 2026. The CVE was subsequently rejected by the CVE Program on the basis that the issue stems from an external dependency rather than a core uTLS defect. Community reaction has been minimal given the low severity and narrow impact scope (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."