{"schema_version":"1.7.3","id":"GO-2026-4509","published":"2026-02-24T23:10:26Z","modified":"2026-02-24T23:41:14.415506Z","aliases":["CVE-2026-27017","GHSA-7m29-f4hw-g2vx"],"summary":"Fingerprint vulnerability in uTLS from GREASE ECH mismatch for Chrome parrots in github.com/refraction-networking/utls","details":"Fingerprint vulnerability in uTLS from GREASE ECH mismatch for Chrome parrots in github.com/refraction-networking/utls","affected":[{"package":{"name":"github.com/refraction-networking/utls","ecosystem":"Go","purl":"pkg:golang/github.com/refraction-networking/utls"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.6.0"},{"fixed":"1.8.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/refraction-networking/utls","symbols":["BoringGREASEECH","Roller.Dial","UConn.BuildHandshakeState","UConn.BuildHandshakeStateWithoutSession","UConn.Handshake","UConn.HandshakeContext","UConn.Read","UConn.Write","UQUICConn.HandleData","UQUICConn.Start","UTLSIdToSpec"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4509.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/refraction-networking/utls/security/advisories/GHSA-7m29-f4hw-g2vx"},{"type":"FIX","url":"https://github.com/refraction-networking/utls/commit/24bd1e05a788c1add7f3037f4532ea552b2cee07"},{"type":"WEB","url":"https://github.com/refraction-networking/utls/releases/tag/v1.8.1"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4509"}}