CVE-2025-58189

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Scoring

Severity
MEDIUM
CVSS base score
5.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS probability
0.44%
Published
2025-10-29
Last modified
2026-09-14

Affected products

Markdown version · Browse all CVEs