alpine · CVE-2026-32283

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2026-32283: 1 source package rows (go); 100 state rows across 2 repos (3.23-community, edge-community); fixed 2, open 98.

Description:

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

cvelogic Threat Intelligence