AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-42505

MEDIUM · CVSS 5.3 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability allows a passive network observer to de-anonymize handshakes utilizing Encrypted Client Hello by exposing pre-shared key identities in the unencrypted client hello message. This could lead to potential privacy breaches for users relying on this encryption method. Organizations that implement Encrypted Client Hello should prioritize addressing this issue to safeguard user anonymity and data integrity.

CVE
CVE-2026-42505
Severity
MEDIUM
CVSS
5.3
EPSS
0.38%

Original NVD Description

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Related CVEs

Other vulnerabilities affecting the same vendor(s)