ALPN negotiation error contains attacker controlled information in crypto/tls
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
02 / AFFECTED SOFTWARE
Affected packages
149 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
05 / REFERENCES
Further evidence
- https://go.dev/cl/707776
- https://go.dev/issue/75652
- https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI
- http://www.openwall.com/lists/oss-security/2025/10/08/1
- https://nvd.nist.gov/vuln/detail/CVE-2025-58189
- https://pkg.go.dev/vuln/GO-2025-4008
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58189.json
- https://pkg.go.dev