s2n-tls Patches Two Critical TLS 1.3 Vulnerabilities
s2n-tls (AWS's open-source TLS/SSL library) has two security issues requiring immediate attention. CVE-2026-16317 lets attackers silently drop TLS 1.3 encrypted records without detection due to missing content_type validation. CVE-2026-16318 causes memory leaks in QUIC-enabled deployments during HelloRetryRequest handshakes. Update to v1.7.6 or later—all TLS 1.3 users are affected by the first flaw.