Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-58189

Опубликовано: 29 окт. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

EPSS

Процентиль: 4%
0.0002
Низкий

5.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

msrc
3 месяца назад

ALPN negotiation error contains attacker controlled information in crypto/tls

CVSS3: 5.3
debian
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains a ...

CVSS3: 5.3
github
3 месяца назад

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость компонента crypto/tls языка программирования Go, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 4%
0.0002
Низкий

5.3 Medium

CVSS3

Дефекты