Executive brief
A privacy flaw was identified in the Go programming language's standard networking library. This library is used by developers to secure internet communications. An attacker monitoring network traffic could potentially identify which server a user is connecting to, even when privacy-enhancing features like Encrypted Client Hello (ECH) are enabled. This undermines the anonymity protections intended to hide user browsing habits from network observers.
Technical details
A privacy vulnerability exists in the Go crypto/tls package's implementation of Encrypted Client Hello (ECH). The 'outer' (unencrypted) Client Hello message incorrectly includes pre-shared key (PSK) identities that should only be present in the 'inner' (encrypted) handshake. A passive network observer capable of capturing TLS handshakes can use these leaked identities to determine the target server's hostname, effectively bypassing the anonymity protections provided by ECH. The issue affects several core handshake functions including Conn.Handshake and Dial. Patches are available in Go versions 1.25.12, 1.26.5, and 1.27.0-rc.2.
Affected products
- Go Project crypto/tls (Go standard library) < 1.25.12, >= 1.26.0-0 < 1.26.5, >= 1.27.0-0 < 1.27.0-rc.2
Timeline
- 2026-05-08: other: Issue reported to Go project
- 2026-07-07: advisory: Go vulnerability report GO-2026-5856 published
- 2026-07-08: disclosed: CVE-2026-42505 published