Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxq7-xw9v-rcv3

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

EPSS

Процентиль: 11%
0.00038
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
27 дней назад

[crypto/tls: ALPN negotiation errors can contain arbitrary text]

CVSS3: 5.3
nvd
7 дней назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

msrc
6 дней назад

ALPN negotiation error contains attacker controlled information in crypto/tls

CVSS3: 5.3
debian
7 дней назад

When Conn.Handshake fails during ALPN negotiation the error contains a ...

suse-cvrf
16 дней назад

Security update for go1.24

EPSS

Процентиль: 11%
0.00038
Низкий

5.3 Medium

CVSS3