{"schema_version":"1.7.5","id":"GO-2026-5856","published":"2026-07-07T21:34:47Z","modified":"2026-07-31T10:44:49.202644503Z","aliases":["BIT-golang-2026-42505","CVE-2026-42505"],"related":["CGA-c2qp-qchh-369w","RHSA-2026:36477","RHSA-2026:36510","RHSA-2026:37435","RHSA-2026:37436","RHSA-2026:38995"],"summary":"Invoking Encrypted Client Hello privacy leak in crypto/tls","details":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.","affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.12"},{"introduced":"1.26.0-0"},{"fixed":"1.26.5"},{"introduced":"1.27.0-0"},{"fixed":"1.27.0-rc.2"}]}],"ecosystem_specific":{"imports":[{"path":"crypto/tls","symbols":["Conn.Handshake","Conn.HandshakeContext","Conn.Read","Conn.Write","Dial","DialWithDialer","Dialer.Dial","Dialer.DialContext","QUICConn.HandleData","QUICConn.SendSessionTicket","QUICConn.Start","clientHelloMsg.marshalMsg"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5856.json"}}],"references":[{"type":"FIX","url":"https://go.dev/cl/775960"},{"type":"REPORT","url":"https://go.dev/issue/79282"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5856"},"credits":[{"name":"Coia Prant (github.com/rbqvq)"}]}