Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42505

Опубликовано: 08 июл. 2026
Источник: debian

Описание

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.27fixed1.27~rc2-1package
golang-1.26fixed1.26.5-1package
golang-1.25fixed1.25.12-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19not-affectedbookwormpackage
golang-1.15not-affectedpackage

Примечания

  • crypto/tls client Encrypted Client Hello introduced in Go 1.23 (issue #63369)

  • https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc

  • https://github.com/golang/go/issues/79282

  • Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5)

  • Fixed by: https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 (go1.25.12)

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

CVSS3: 5.3
redhat
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

CVSS3: 5.3
nvd
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

msrc
23 дня назад

Invoking Encrypted Client Hello privacy leak in crypto/tls

CVSS3: 5.3
github
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.