Junglewise Threat Intelligence

CVE-2026-26994: GO-2025-3638 - ServerHellos are accepted without checking TLS 1.3 downgrade canaries in github.com/refraction-networking/utls

CVE-2026-26994 · Severity: low · CVSS 3.1 · Published 2025-04-24

Technologies: github.com/refraction-networking/utls (Go). Vendors: Go.

Executive brief

ServerHellos are accepted without checking TLS 1.3 downgrade canaries in github.com/refraction-networking/utls

Affected products

  • Go github.com/refraction-networking/utls

Related threats