Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxq7-xw9v-rcv3

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

EPSS

Процентиль: 35%
0.00436
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 месяцев назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

CVSS3: 5.3
redhat
11 месяцев назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

CVSS3: 5.3
nvd
11 месяцев назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

msrc
11 месяцев назад

ALPN negotiation error contains attacker controlled information in crypto/tls

CVSS3: 5.3
debian
11 месяцев назад

When Conn.Handshake fails during ALPN negotiation the error contains a ...

EPSS

Процентиль: 35%
0.00436
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-532