| Name | CVE-2026-26994 |
| Description | uTLS is a fork of crypto/tls, created to customize ClientHello for fin ... |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1129011 |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
[trixie] - golang-refraction-networking-utls <no-dsa> (Minor issue)
[bookworm] - golang-refraction-networking-utls <no-dsa> (Minor issue)
[bullseye] - golang-refraction-networking-utls <ignored> (Limited support, no binaries built with it)
https://github.com/refraction-networking/utls/security/advisories/GHSA-pmc3-p9hx-jq96
Fixed by: https://github.com/refraction-networking/utls/commit/f8892761e2a4d29054264651d3a86fda83bc83f9 (v1.7.0)