Overview
What is CVE-2026-42505?
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Vulnerability intelligence
CVE-2026-42505 and is rated Medium severity with a CVSS score of 5.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.