如果未定义 , 不会返回一个完整的会话对象(session object),而是返回一个形如 的 引用,指向进程全局的 。此时, 仅根据该哈希值进行验证。 由于 TLS 1.2 的会话 ID 由服务器选择并以明文形式发送, 会将具有相同会话 ID 的其他服务器的会话匹配到缓存中,并用该服务器的主密钥(master secret)、密码套件(cipher suite)和协议版本覆盖客户端本地的会话条目,而引用句柄(handle)仍继续有效。在写路径上,没有任何机制比较对等方、应用程序配置的服务端 ID 或 。因此,通
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93302 | 8.3 HIGH | Trusted peer certificate match ignores public key, allowing forged CA clones |
| CVE-2026-89136 | 8.3 HIGH | Client accepts unsolicited RawPublicKey server certificate type |
| CVE-2026-89102 | 8.3 HIGH | OCSP stapling v2 multi accepts non-CA chain certificates as issuers |
| CVE-2026-93304 | 6.3 MEDIUM | (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange |
| CVE-2026-89133 | 6.3 MEDIUM | NameConstraints not enforced across unconstrained intermediate CA |
| CVE-2026-89134 | 6.3 MEDIUM | Subject CN name-constraint check bypassed when non-DNS SAN present |
| CVE-2026-89135 | 6.3 MEDIUM | Failed X509_verify_cert leaves unverified CA in shared CertManager |
| CVE-2026-15442 | 2.3 LOW | Heap use-after-free on read during bidirectional (D)TLS shutdown |
| CVE-2026-94418 | 2.3 LOW | Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY |
| CVE-2026-94417 | 2.3 LOW | CRL check skipped when OCSP enabled and certificate has no OCSP URL |
No comments yet