Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxq7-xw9v-rcv3

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

EPSS

Процентиль: 4%
0.0002
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

CVSS3: 5.3
nvd
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

msrc
3 месяца назад

ALPN negotiation error contains attacker controlled information in crypto/tls

CVSS3: 5.3
debian
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains a ...

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость компонента crypto/tls языка программирования Go, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 4%
0.0002
Низкий

5.3 Medium

CVSS3