CVE-2026-32283Disclosure(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770CWE-764

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-07-13: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-15: 104-0804-1504-1704-1807-13
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2General1
2026-04-151
Disclosure1
2026-04-171
Patch1
2026-04-181
General1
2026-07-131
General1
Full discourse7 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Elastic ❗ CVE-2026-49091 ❗ CVE-2026-32283 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-elastic-4/ https://t.co/Qjp3pVsUu3

    Post summary

    The tweet announces new Elastic product vulnerability CVEs and links to a government site for more information, but does not provide technical details, PoC, or patch information.

    00000208
    6.7K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-32283 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/460 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog notes that CVE‑2026‑32283 has been removed from the latest AWS Lambda base image scans, implying remediation but providing no further technical detail.

    0000042
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32283 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/460 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE-2026-32283 has been removed from the latest AWS Lambda base images, indicating it has been patched and is no longer present in the container environment.

    0000020
    34 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenTofu, Denial of Service, #CVE-2026-32280, #CVE-2026-32281, #CVE-2026-32283, #CVE-2026-32288 (Medium) https://dailycve.com/opentofu-denial-of-service-cve-2026-32280-cve-2026-32281-cve-2026-32283-cve-2026-32288-medium/

    Post summary

    The post announces a group of OpenTofu denial‑of‑service vulnerabilities (CVE‑2026‑32280, 32281, 32283, 32288) with a medium CVSS score, but provides no exploit details, PoC, or patch information.

    0000015
    181 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32283 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/460 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A newly detected CVE-2026-32283 impacting AWS Lambda base image stdlib is announced with issue‑track references, but no exploitation, patch, or detailed technical data is provided.

    0000047
    31 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32283 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32283 #CVE-2026-32283 #CVE #CyberSecurity #InfoSec https://t.co/AYyZ9k8d2k

    Post summary

    The tweet announces CVE-2026-32283 with limited details, merely linking to the NVD record and offering no technical, exploit, or remediation information.

    0000044
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32283 If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption … https://www.cve.org/CVERecord?id=CVE-2026-32283

    Post summary

    A denial‑of‑service vulnerability in TLS occurs when a side sends multiple key update messages in one record, causing a deadlock and resource exhaustion.

    00000133
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more