CVE-2026-27017Disclosure(refraction-networking / utls)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cipher suite in the outer ClientHello and for ECH, it does so consistently based on hardware support—for example, if it prefers AES for the outer cipher suite, it also uses AES for ECH. However, the Chrome parrot in uTLS hardcodes AES preference for outer cipher suites but selects the ECH cipher suite randomly between AES and ChaCha20. This creates a 50% chance of selecting ChaCha20 for ECH while using AES for the outer cipher suite, a combination impossible in Chrome. This issue only affects GREASE ECH; in real ECH, Chrome selects the first valid cipher suite when AES is preferred, which uTLS handles correctly. This issue has been fixed in version 1.8.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1240

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • utls

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
utls

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Technical Details · 2026-02-20: 102-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27017 Fingerprinting Inconsistency in uTLS GREASE ECH Cipher Suite Selection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27017

    Post summary

    CVE-2026-27017 is disclosed as a vulnerability related to inconsistent cipher‑suite selection in uTLS GREASE ECH, highlighting a potential fingerprinting flaw.

    0000034
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27017 uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 cont… https://www.cve.org/CVERecord?id=CVE-2026-27017

    Post summary

    The post merely cites CVE-2026-27017 in the context of the uTLS fork, lacking specific vulnerability, exploitation, or mitigation details.

    0000063
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprefraction-networkingutls-go-

Explore more