Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42505

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия до 1.25.12 (исключая)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия от 1.26.0 (включая) до 1.26.5 (исключая)
cpe:2.3:a:golang:go:1.27:rc1:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00382
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

CVSS3: 5.3
redhat
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

msrc
23 дня назад

Invoking Encrypted Client Hello privacy leak in crypto/tls

CVSS3: 5.3
debian
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by ...

CVSS3: 5.3
github
29 дней назад

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

EPSS

Процентиль: 31%
0.00382
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201