Логотип exploitDog
bind:CVE-2025-68121
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68121

Количество 12

Количество 12

ubuntu логотип

CVE-2025-68121

24 дня назад

[crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain]

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2025-68121

3 дня назад

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2025-68121

3 дня назад

During session resumption in crypto/tls, if the underlying Config has ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-h355-32pf-p2xm

3 дня назад

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20085-1

17 дней назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20077-1

18 дней назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0219-1

18 дней назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0218-1

18 дней назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0308-1

12 дней назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0296-1

14 дней назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0298-1

13 дней назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0297-1

13 дней назад

Security update for go1.25-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-68121

[crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain]

CVSS3: 4.8
0%
Низкий
24 дня назад
nvd логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 4.8
0%
Низкий
3 дня назад
debian логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has ...

CVSS3: 4.8
0%
Низкий
3 дня назад
github логотип
GHSA-h355-32pf-p2xm

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 4.8
0%
Низкий
3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20085-1

Security update for go1.25

17 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20077-1

Security update for go1.24

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0219-1

Security update for go1.24

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0218-1

Security update for go1.25

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0308-1

Security update for go1.24-openssl

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:0296-1

Security update for go1.24-openssl

14 дней назад
suse-cvrf логотип
SUSE-SU-2026:0298-1

Security update for go1.25-openssl

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0297-1

Security update for go1.25-openssl

13 дней назад

Уязвимостей на страницу