ZeroHour

CVE-2025-58189

CVSS 3.1
5.3 medium
EPSS
<1%p37
Published
()
Modified
Description

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Vendors
golang
Products
go
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.