Unrated severityNVD Advisory· Published Oct 29, 2025· Updated Nov 4, 2025
ALPN negotiation error contains attacker controlled information in crypto/tls
CVE-2025-58189
Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Affected products
1- Go standard library/crypto/tlsv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.