When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
History

Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang crypto
Vendors & Products Golang
Golang crypto

Fri, 31 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-117
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
Description When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Title ALPN negotiation error contains attacker controlled information in crypto/tls
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2025-10-29T22:10:12.947Z

Updated: 2025-10-30T20:34:44.764Z

Reserved: 2025-08-27T14:50:58.692Z

Link: CVE-2025-58189

cve-icon Vulnrichment

Updated: 2025-10-30T20:34:39.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-29T23:16:19.833

Modified: 2025-10-30T21:15:34.127

Link: CVE-2025-58189

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-29T22:10:12Z

Links: CVE-2025-58189 - Bugzilla