VDB
DEBIAN-CVE-2025-58189
DEBIAN-CVE-2025-58189
PUBLISHED
CVSS 5.300000190734863 MEDIUM
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | golang-1.25 | 1.25.0-2, 1.25.0-1, 0 |
| Debian:11 | golang-1.15 | 1.15.15-1, 1.15.15-1, 1.15.15-1 |
| Debian:13 | golang-1.24 | 1.24.8-1, 1.24.13-1, 1.24.13-2 |
| Debian:12 | golang-1.19 | 0, 1.19.9-1, 1.19.8-2 |
Timeline
- Oct 29, 2025 CVE Published
- Apr 28, 2026 CVE Updated