CVE-2026-97031: 
cAdvisor vulnerability analysis and mitigation

Overview

CVE-2026-97031 is a Denial of Service vulnerability in Go's crypto/tls standard library package caused by improper handling of multiple ECH (Encrypted Client Hello) outer extension references during TLS handshakes. RFC 9849 prohibits multiple ECH outer extension references, but prior to the fix, a remote unauthenticated client could send a well-crafted packet specifying multiple such references, triggering memory exhaustion in the server process. Affected versions include Go crypto/tls before 1.26.9 and versions 1.27.0-0 through before 1.27.2. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). The Go crypto/tls implementation failed to validate that ECH outer extension references appeared only once per TLS ClientHello packet, as required by RFC 9849; when multiple references were present, the library would copy outer extensions multiple times, creating a memory amplification vector. An unauthenticated attacker can exploit this remotely (network-accessible, no privileges or user interaction required) by sending a specially crafted TLS ClientHello packet with multiple ECH outer extension references to any Go server using the affected crypto/tls package. The fix rejects such packets as malformed before the amplification can occur (Red Hat Bugzilla, Go Issue, Go CL).

Impact

Successful exploitation causes memory exhaustion in the server process, resulting in a Denial of Service condition with high availability impact. There is no confidentiality or integrity impact — the vulnerability is purely a resource exhaustion issue. Any Go application using the crypto/tls package for TLS server functionality and running a vulnerable version is at risk, potentially causing service outages for all clients connecting to the affected server (Red Hat Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is 0.0, reflecting the current low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and is remotely exploitable over the network, lowering the barrier for potential future exploitation.

Exploitation steps

  1. Reconnaissance: Identify internet-facing services built with Go that use the crypto/tls package for TLS server functionality and are running Go versions prior to 1.26.9 or between 1.27.0-0 and 1.27.2. Tools such as Shodan or Censys can be used to enumerate TLS-enabled Go services.
  2. Craft malicious TLS ClientHello: Construct a TLS ClientHello packet that includes multiple ECH (Encrypted Client Hello) outer extension references — a structure explicitly prohibited by RFC 9849 but not previously rejected by vulnerable Go versions.
  3. Send packet to target: Transmit the malformed ClientHello to the target server's TLS port (typically 443 or another configured TLS port) without requiring any credentials or prior session.
  4. Trigger memory exhaustion: The vulnerable crypto/tls implementation processes the multiple ECH outer extension references, copying outer extensions multiple times and causing unbounded memory allocation, leading to server process memory exhaustion and Denial of Service (Red Hat Bugzilla, Go Issue).

Indicators of compromise

  • Network: Unusual volume of TLS ClientHello packets from a single or distributed source targeting TLS-enabled Go services; packets with anomalous ECH extension structures detectable via deep packet inspection.
  • Logs: Server-side TLS handshake errors or abrupt connection terminations logged in application or system logs; out-of-memory (OOM) events in system logs (e.g., Linux kernel OOM killer messages) associated with the Go server process.
  • Process: Rapid, sustained growth in memory consumption of the Go server process without a corresponding increase in legitimate client connections; process crashes or restarts due to memory exhaustion.

Mitigation and workarounds

Upgrade to Go 1.26.9 or Go 1.27.2 (or later), which reject malformed ECH outer extension references before memory amplification can occur (Go CL, Go Vuln DB). Organizations unable to upgrade immediately should consider placing a TLS-terminating reverse proxy or load balancer in front of affected Go services to filter malformed TLS handshakes. Monitor the Go security announcements mailing list for further guidance (golang-announce).

Community reactions

The vulnerability was disclosed via the golang-announce mailing list and tracked under Go vulnerability identifier GO-2026-6607. Red Hat opened a high-severity bug report (Bug 2548336) and published a security advisory. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related cAdvisor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97031HIGH7.5
  • cAdvisor logocAdvisor
  • prometheus-statsd-exporter-fips-0.22
NoYesOct 08, 2026
CVE-2026-94440HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-elasticache-fips
NoYesOct 08, 2026
CVE-2026-94448MEDIUM6.1
  • cAdvisor logocAdvisor
  • longhorn-share-manager-fips-1.9
NoYesOct 08, 2026
CVE-2026-97032MEDIUM5.9
  • cAdvisor logocAdvisor
  • task
NoYesOct 08, 2026
CVE-2026-97030NONEN/A
  • cAdvisor logocAdvisor
  • cluster-api-1.14
NoYesOct 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management