CVE-2026-56862: 
Go vulnerability analysis and mitigation

Overview

CVE-2026-56862 is a Denial of Service vulnerability in the Go standard library's crypto/tls package, caused by improper handling of TLS handshake messages such as KeyUpdate. A malicious client can repeatedly send KeyUpdate messages — even before a handshake is completed — forcing the server to perform computationally expensive key derivation operations indefinitely. Affected versions include Go crypto/tls prior to 1.25.13, 1.26.0–1.26.5, and 1.27.0-0 through 1.27.0-rc.2. It was published on August 13, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is that KeyUpdate handshake messages in Go's crypto/tls implementation are unconditionally treated as state-advancing, regardless of whether the TLS handshake has been completed (CWE-770: Allocation of Resources Without Limits or Throttling; CWE-1050: Excessive Platform Resource Consumption within a Loop). An unauthenticated remote attacker can establish a TLS connection and flood the server with KeyUpdate messages, triggering repeated HKDF-based key derivation operations without any rate limiting or validation that a full handshake has occurred. No authentication or user interaction is required, and the attack is fully automatable over the network. The fix is tracked in Go issue #80528 and code change CL 804261 (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation results in a Denial of Service against any Go application using the crypto/tls package for TLS server functionality. The server's CPU resources are exhausted by continuous key derivation operations, degrading or completely disabling service availability. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue affecting any service built on vulnerable Go versions (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is rated automatable by NVD SSVC, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.185% (Feedly data) to 0.568% (GitHub Advisory), placing it in a moderate percentile for near-term exploitation likelihood. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing services built with vulnerable Go versions (prior to 1.25.13, 1.26.6, or 1.27.0-rc.3) that expose TLS endpoints, using tools like Shodan, Censys, or banner grabbing.
  2. Establish TLS connection: Initiate a TLS connection to the target server without completing the full handshake negotiation.
  3. Send repeated KeyUpdate messages: Continuously transmit KeyUpdate handshake messages to the server before or during the handshake phase, exploiting the lack of validation that a handshake has been completed.
  4. Resource exhaustion: The server processes each KeyUpdate message as state-advancing and performs a full HKDF key derivation operation for each, consuming CPU resources indefinitely.
  5. Denial of Service achieved: With sufficient message volume, the server's CPU is saturated, causing degraded response times or complete service unavailability for legitimate clients (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unusually high volume of TLS KeyUpdate handshake messages from a single or small set of source IPs; TLS connections that remain open without completing the handshake while generating sustained CPU load on the server.
  • System: Sustained high CPU utilization on Go-based TLS server processes without a corresponding increase in legitimate application traffic or request throughput.
  • Logs: Application or system logs showing repeated TLS handshake state transitions or key derivation events without corresponding completed handshake entries; connection logs showing long-lived TLS sessions with minimal data transfer.

Mitigation and workarounds

Upgrade to a patched version of the Go standard library: Go 1.25.13, Go 1.26.6, or Go 1.27.0-rc.3 or later. Red Hat has issued errata for affected products: RHSA-2026:60304 (RHEL 9), RHSA-2026:60305 (RHEL 8), and RHSA-2026:60306 (RHEL 10). SUSE has released updates SUSE-SU-2026:3640-1, SUSE-SU-2026:3799-1, SUSE-SU-2026:3815-1, and SUSE-SU-2026:3830-1. As a temporary workaround, consider implementing network-level rate limiting on TLS connections or deploying a TLS-terminating proxy with connection throttling in front of vulnerable services (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The Go team disclosed the vulnerability via the golang-announce mailing list and published a fix through the standard Go release process. Red Hat triaged the issue at high severity and issued errata across RHEL 8, 9, and 10. The vulnerability was also discussed on the oss-security mailing list and picked up by Linux security news outlets including Pro-Linux.de and LinuxSecurity.com. Community reaction has been measured, consistent with a DoS-only vulnerability with no public exploit code (golang-announce, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

golang-1.19

Affected

sid

golang-1.27: 1.27~rc3-1

Fixed

trixie

golang-1.24

Affected

Ubuntu

Unknown

bionic (esm-apps)

golang-1.8

Unknown

bionic (esm-infra)

golang-1.10

Unknown

devel

golang-1.24

Unknown

focal (esm-apps)

golang-1.16

Unknown

focal (esm-infra)

golang-1.13

Unknown

jammy

golang-1.13

Unknown

jammy (esm-apps)

golang-1.13

Unknown

noble

golang-1.21

Unknown

RHEL / CentOS

Fixed

OpenShift

el8:cri-o/cri-o-0:1.25.5-37.rhaos4.12.git2e7f657.el8

Fixed

RHEL 8

:appstream:container-tools:rhel8/skopeo/containers-common

Fixed

RHEL 9

:appstream:delve-0:1.26.1-1.el9_2.1.src

Fixed

RHEL 10

delve-0:1.26.1-2.el10_0.src

Fixed

Source: This report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56865HIGH8.4
  • Go logoGo
  • dapr-operator-1.17
NoYesAug 13, 2026
CVE-2026-56864HIGH7.5
  • Go logoGo
  • trivy
NoYesAug 13, 2026
CVE-2026-56862HIGH7.5
  • Go logoGo
  • hcloud
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • Go logoGo
  • custom-pod-autoscaler-operator-fips
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • Go logoGo
  • x509-certificate-exporter-fips
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management