Skip to content

[GHSA-wj64-gh9j-xm82] Issue summary: An OpenSSL TLS 1.3 server may fail to...#7312

Closed
vdukhovni wants to merge 1 commit into
vdukhovni/advisory-improvement-7312from
vdukhovni-GHSA-wj64-gh9j-xm82
Closed

[GHSA-wj64-gh9j-xm82] Issue summary: An OpenSSL TLS 1.3 server may fail to...#7312
vdukhovni wants to merge 1 commit into
vdukhovni/advisory-improvement-7312from
vdukhovni-GHSA-wj64-gh9j-xm82

Conversation

@vdukhovni
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • Description
  • Severity
  • Summary

Comments
It makes no sense to give this CVE a HIGH rating. I barely convinced the OpenSSL security response team to assign a CVE at all. This is a deviation from documented behaviour, but there's no attack vector, other than perhaps record all the traffic, and perhaps someday decrypt, but only relevant under the multiple uncommon conditions that result in the deviation from documented behaviour.

@github-actions github-actions Bot changed the base branch from main to vdukhovni/advisory-improvement-7312 April 7, 2026 05:42
@yhidad31
Copy link
Copy Markdown

yhidad31 commented Apr 8, 2026

Hi @vdukhovni, unfortunately, we are unable to update CVE-2026-2673 because the ID was issued by CISA-ADP. GitHub is not the assigning CNA for this CVE. To get it updated, you need to contact CISA-ADP at contact@mail.cisa.dhs.gov.

@yhidad31 yhidad31 closed this Apr 8, 2026
@github-actions github-actions Bot deleted the vdukhovni-GHSA-wj64-gh9j-xm82 branch April 8, 2026 21:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants