Executive brief
ServerHellos are accepted without checking TLS 1.3 downgrade canaries in github.com/refraction-networking/utls
Affected products
- Go github.com/refraction-networking/utls
Junglewise Threat Intelligence
CVE-2026-26994 · Severity: low · CVSS 3.1 · Published 2025-04-24
Technologies: github.com/refraction-networking/utls (Go). Vendors: Go.
ServerHellos are accepted without checking TLS 1.3 downgrade canaries in github.com/refraction-networking/utls