根据 RFC 9849 的规定,不允许在 ECH(Encrypted Client Hello,加密客户端 hello)外层扩展中存在多个引用。此前,攻击者可以通过构造包含多个引用的恶意数据包,导致服务器进程出现内存耗尽问题。现在我们将其视为格式错误的报文并予以拒绝,从而有效遏制由此引发的内存放大攻击向量。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go standard library | crypto/tls | 0 ~ 1.26.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94439 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http | |
| CVE-2026-94440 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart | |
| CVE-2026-94448 | Reset context tracking on consecutive template expressions in html/template | |
| CVE-2026-56857 | Root.Mkdir(All) can follow junctions out of the root on Windows in os | |
| CVE-2026-56866 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http | |
| CVE-2026-78659 | HTTP/2 server memory exhaustion due to Trailer headers in net/http | |
| CVE-2026-78660 | HTTP/2 transport accepts malformed framing-related headers in net/http | |
| CVE-2026-78663 | Double flow control refund on HTTP/2 server streams in net/http | |
| CVE-2026-78667 | Lack of limit on size of parsed Range headers in net/http | |
| CVE-2026-78669 | Excessive CPU consumption from repeated initial window changes in net/http | |
| CVE-2026-97032 | HTTP/2 server crash due to HPACK encoder race in net/http | |
| CVE-2026-97030 | Recognize yield as regexp preceder keyword in html/template |
No comments yet