Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Medium CVSS 5.3
Summary
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://go.dev/cl/775960 Patch
- https://go.dev/issue/79282 Issue Tracking
- https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc Mailing List
- https://pkg.go.dev/vuln/GO-2026-5856 Vendor Advisory
Timeline
- nvd_ingest NVD