VulnerabilityAnalyzed
CVE-2025-58189
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
MEDIUM 5.3EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- golang/go
- Source
- security@golang.org
References
- https://go.dev/cl/707776Patch
- https://go.dev/issue/75652Issue Tracking
- https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bIMailing List, Release Notes
- https://pkg.go.dev/vuln/GO-2025-4008Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/10/08/1Mailing List, Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.