CVE-2026-97031
Received Received - Intake

ECH Outer Extension References Memory Exhaustion in Go

Vulnerability report for CVE-2026-97031, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Go standard library crypto/tls 0
Go standard library crypto/tls 1.27.0-0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the improper handling of multiple ECH outer extension references in the Go standard library's crypto/tls package. RFC 9849 does not permit multiple references, but a crafted packet could exploit this to cause memory exhaustion in the server process by triggering excessive memory usage.

Impact Analysis

If you are running a server using the affected Go standard library crypto/tls package, an attacker could send specially crafted packets to exhaust server memory, leading to degraded performance or a denial-of-service condition.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a memory exhaustion issue in the Go standard library's crypto/tls implementation. Compliance impacts would depend on how the affected software is used in a system handling regulated data.

Mitigation Strategies

Update Go to the latest version to ensure the fix for CVE-2026-97031 is applied. Monitor network traffic for malformed packets attempting to exploit this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97031. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart