Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not
Details
CVE-2026-56862 affects multiple packages. Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. See references for individual vulnerability details.