# CVE-2025-61730

## Summary

- **CVE ID:** CVE-2025-61730
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** N/A
- **Published:** Jan 28, 2026
- **Last Modified:** Sep 14, 2026

## Description

During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

## Affected Products

- Go standard library — crypto/tls (0)
- Go standard library — crypto/tls (1.25.0)

## References

- [CNA](https://go.dev/cl/724120)
- [CNA](https://go.dev/issue/76443)
- [CNA](https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc)
- [CNA](https://pkg.go.dev/vuln/GO-2026-4340)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._