During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Jan 29, 2026 | Jan 28, 2026 |
| Amazon Linux Ami 2 | — | Upgrade golistUpgrade oci-add-hooksUpgrade soci-snapshotterUpgrade amazon-ecr-credential-helperUpgrade golang-srcUpgrade oci-add-hooks-debuginfoUpgrade golangUpgrade cni-plugins-debuginfoUpgrade golang-sharedUpgrade runc-debuginfoUpgrade amazon-cloudwatch-agentUpgrade cri-toolsUpgrade golist-debuginfoUpgrade golang-miscUpgrade docker-debuginfoUpgrade containerd-debuginfoUpgrade cri-tools-debuginfoUpgrade golang-github-cpuguy83-go-md2manUpgrade runcUpgrade golang-binUpgrade cni-pluginsUpgrade dockerUpgrade nerdctlUpgrade ecs-initUpgrade nerdctl-debuginfoUpgrade golang-testsUpgrade containerd-stressUpgrade golang-docsUpgrade runfinch-finchUpgrade containerdUpgrade amazon-ecr-credential-helper-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade credentials-fetcher | May 28, 2026 | Jan 28, 2026 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Jun 26, 2026 | Jun 25, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 28, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub