CVE-2026-97031 PUBLISHED

Reject malformed ECH outer extension references in crypto/tls

Assigner: Go
Reserved: 23.09.2026 Published: 08.10.2026 Updated: 08.10.2026

Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.

Product Status

Vendor Go standard library
Product crypto/tls
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

References

Problem Types

  • CWE-405: Asymmetric Resource Consumption