CVE-2026-27017: 
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-27017 is a fingerprint mismatch vulnerability in the uTLS library (a fork of Go's crypto/tls) that allows network observers to identify clients using Chrome-parrot TLS fingerprinting when GREASE ECH is active. The flaw affects github.com/refraction-networking/utls versions 1.6.0 through 1.8.0 (Go module). It was reported by Telegram user @acgdaily, published on February 17, 2026, and patched in version 1.8.1. The CVSS v3.1 base score is 5.3 (Medium), while the CVSS v4.0 base score is 2.3 (Low) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-1240 (Use of a Cryptographic Primitive with a Risky Implementation) and CWE-358 (Improperly Implemented Security Check for Standard). uTLS's Chrome parrot profiles (HelloChrome_120, HelloChrome_120_PQ, HelloChrome_131, HelloChrome_133) hardcode AES preference for the outer ClientHello ciphersuite but randomly select between AES and ChaCha20 for the GREASE ECH ciphersuite. In real Chrome, both selections are made consistently based on hardware AES acceleration support — meaning the AES-outer + ChaCha20-ECH combination produced by uTLS ~50% of the time is cryptographically impossible in genuine Chrome. This inconsistency is detectable by a passive network observer and does not affect real (non-GREASE) ECH, where uTLS correctly mirrors Chrome's behavior. The fix is tracked in commit 24bd1e05a788c1add7f3037f4532ea552b2cee07 (GitHub Advisory, Red Hat Bugzilla).

Impact

The primary impact is a limited confidentiality breach: a passive network observer can distinguish uTLS-based clients from genuine Chrome browsers with approximately 50% probability per connection when GREASE ECH is in use, effectively de-anonymizing or fingerprinting tools that rely on uTLS's Chrome impersonation for censorship circumvention or privacy. There is no integrity or availability impact, and no remote code execution or data exfiltration is possible through this vulnerability. The affected scope is limited to applications using the Chrome parrot profiles in uTLS versions 1.6.0–1.8.0 that depend on TLS fingerprint indistinguishability for their security model (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only passive network observation — no authentication or special privileges — but the attacker must be positioned to observe TLS handshakes and the impact is limited to client identification rather than system compromise (GitHub Advisory).

Exploitation steps

  1. Positioning: An attacker (e.g., a network operator, ISP, or DPI system) positions themselves to passively observe TLS handshakes between a uTLS-based client and a server supporting ECH.
  2. Capture ClientHello: The observer captures the TLS ClientHello messages from the target client.
  3. Analyze ciphersuite selection: The observer inspects the outer ClientHello ciphersuite and the GREASE ECH ciphersuite. In genuine Chrome, both are selected consistently (e.g., both AES or both ChaCha20 based on hardware support).
  4. Detect mismatch: If the outer ciphersuite is AES but the ECH ciphersuite is ChaCha20, this combination is impossible in real Chrome, revealing the client is using uTLS versions 1.6.0–1.8.0 with a Chrome parrot profile.
  5. Client identification: The observer can now identify or block the connection as originating from a uTLS-based tool (e.g., a censorship circumvention proxy), undermining the anonymity or bypass capability of the client (GitHub Advisory, Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability is fixed in github.com/refraction-networking/utls version 1.8.1. Developers and operators using uTLS with Chrome parrot profiles should upgrade to v1.8.1 or later immediately. No configuration-based workaround is available for affected versions; the only remediation is upgrading the Go module dependency. Applications using real ECH (not GREASE ECH) are not affected by this issue (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was reported via Telegram by user @acgdaily and promptly addressed by the uTLS maintainer (ewust) with a fix published on February 17, 2026. Red Hat tracked the issue in Bugzilla with a low severity rating. Coverage has appeared in security aggregators and Linux distribution security advisories (including SUSE/openSUSE), reflecting routine upstream dependency patching activity rather than significant community alarm (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

golang-refraction-networking-utls

Fixed

sid

golang-refraction-networking-utls

Fixed

trixie

golang-refraction-networking-utls

Fixed

Ubuntu

Unknown

devel

golang-refraction-networking-utls

Unknown

jammy

golang-refraction-networking-utls

Unknown

jammy (esm-apps)

golang-refraction-networking-utls

Unknown

noble

golang-refraction-networking-utls

Unknown

noble (esm-apps)

golang-refraction-networking-utls

Unknown

resolute

golang-refraction-networking-utls

Unknown

resolute (esm-apps)

golang-refraction-networking-utls

Unknown

Source: This report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103000HIGH8.7
  • Python logoPython
  • litellm-1.101
NoYesSep 30, 2026
CVE-2026-102999HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102998HIGH8.7
  • Python logoPython
  • litellm-1.98
NoYesSep 30, 2026
CVE-2026-102997HIGH8.7
  • Python logoPython
  • pypdf
NoYesSep 30, 2026
CVE-2026-77387MEDIUM4
  • Python logoPython
  • superset-6.1
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management