Name
CVE-2025-58189
Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://go.dev/issue/75652Issue Tracking
https://pkg.go.dev/vuln/GO-2025-4008Vendor Advisory
Analysis#
Vulnerability Ratings#
5.3
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Patched
yocto
scarthgap
1.22.12
Exploitable
Resolved with patches#
go (yocto:scarthgap)
#
Title
Author
Resolve
1
crypto/tls: quote protocols in ALPN error message
Roland Shoemaker <roland@golang.org>
CVE-2025-58189