
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27017 is a fingerprint mismatch vulnerability in the uTLS library (a fork of Go's crypto/tls) that allows network observers to identify clients using Chrome-parrot TLS fingerprinting when GREASE ECH is active. The flaw affects github.com/refraction-networking/utls versions 1.6.0 through 1.8.0 (Go module). It was reported by Telegram user @acgdaily, published on February 17, 2026, and patched in version 1.8.1. The CVSS v3.1 base score is 5.3 (Medium), while the CVSS v4.0 base score is 2.3 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-1240 (Use of a Cryptographic Primitive with a Risky Implementation) and CWE-358 (Improperly Implemented Security Check for Standard). uTLS's Chrome parrot profiles (HelloChrome_120, HelloChrome_120_PQ, HelloChrome_131, HelloChrome_133) hardcode AES preference for the outer ClientHello ciphersuite but randomly select between AES and ChaCha20 for the GREASE ECH ciphersuite. In real Chrome, both selections are made consistently based on hardware AES acceleration support — meaning the AES-outer + ChaCha20-ECH combination produced by uTLS ~50% of the time is cryptographically impossible in genuine Chrome. This inconsistency is detectable by a passive network observer and does not affect real (non-GREASE) ECH, where uTLS correctly mirrors Chrome's behavior. The fix is tracked in commit 24bd1e05a788c1add7f3037f4532ea552b2cee07 (GitHub Advisory, Red Hat Bugzilla).
The primary impact is a limited confidentiality breach: a passive network observer can distinguish uTLS-based clients from genuine Chrome browsers with approximately 50% probability per connection when GREASE ECH is in use, effectively de-anonymizing or fingerprinting tools that rely on uTLS's Chrome impersonation for censorship circumvention or privacy. There is no integrity or availability impact, and no remote code execution or data exfiltration is possible through this vulnerability. The affected scope is limited to applications using the Chrome parrot profiles in uTLS versions 1.6.0–1.8.0 that depend on TLS fingerprint indistinguishability for their security model (GitHub Advisory, Red Hat Bugzilla).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only passive network observation — no authentication or special privileges — but the attacker must be positioned to observe TLS handshakes and the impact is limited to client identification rather than system compromise (GitHub Advisory).
The vulnerability is fixed in github.com/refraction-networking/utls version 1.8.1. Developers and operators using uTLS with Chrome parrot profiles should upgrade to v1.8.1 or later immediately. No configuration-based workaround is available for affected versions; the only remediation is upgrading the Go module dependency. Applications using real ECH (not GREASE ECH) are not affected by this issue (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was reported via Telegram by user @acgdaily and promptly addressed by the uTLS maintainer (ewust) with a fix published on February 17, 2026. Red Hat tracked the issue in Bugzilla with a low severity rating. Coverage has appeared in security aggregators and Linux distribution security advisories (including SUSE/openSUSE), reflecting routine upstream dependency patching activity rather than significant community alarm (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bookworm
golang-refraction-networking-utls
sid
golang-refraction-networking-utls
trixie
golang-refraction-networking-utls
devel
golang-refraction-networking-utls
jammy
golang-refraction-networking-utls
jammy (esm-apps)
golang-refraction-networking-utls
noble
golang-refraction-networking-utls
noble (esm-apps)
golang-refraction-networking-utls
resolute
golang-refraction-networking-utls
resolute (esm-apps)
golang-refraction-networking-utls
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."