CVE-2026-42505: Invoking Encrypted Client Hello privacy leak in crypto/tls
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Goto a version that resolves this vulnerability.Fixed in 1.26.5Patch CVE-2026-39822 - Upgrade
Upgrade
Goto a version that resolves this vulnerability.Fixed in 1.25.12Patch CVE-2026-42505
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42505?
CVE-2026-42505 has a medium severity rating of 5.3.
What does CVE-2026-42505 expose to attackers?
CVE-2026-42505 can lead to the de-anonymization of handshakes using Encrypted Client Hello, allowing attackers to discern pre-shared key identities.
Who is affected by CVE-2026-42505?
CVE-2026-42505 affects software that uses the Google Go crypto/tls library, particularly applications utilizing Encrypted Client Hello.
How can I mitigate CVE-2026-42505?
To mitigate CVE-2026-42505, ensure that your application is updated to the latest version of Google Go that includes fixes for this vulnerability.
When was CVE-2026-42505 published?
CVE-2026-42505 was published on July 8, 2026.