CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
- Published Apr 8, 2026
- CVSS 7.5 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available