VYPR
Unrated severityNVD Advisory· Published Oct 24, 2019· Updated Aug 5, 2024

CVE-2019-17596

CVE-2019-17596

Description

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Affected products

6

Patches

2
ef74bfc859c9

[release-branch.go1.12-security] go1.12.11

https://github.com/golang/goKatie HockmanOct 17, 2019via osv
1 file changed · +1 1
  • VERSION+1 1 modified
    @@ -1 +1 @@
    -go1.12.10
    \ No newline at end of file
    +go1.12.11
    \ No newline at end of file
    
72766093e6bd

[release-branch.go1.13-security] go1.13.2

https://github.com/golang/goKatie HockmanOct 17, 2019via osv
1 file changed · +1 1
  • VERSION+1 1 modified
    @@ -1 +1 @@
    -go1.13.1
    \ No newline at end of file
    +go1.13.2
    \ No newline at end of file
    

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

13

News mentions

0

No linked articles in our index yet.