Go standard library crypto/tls

6 known vulnerabilities in Go standard library crypto/tls, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-56862 CVSS 7.5 high Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or…
  • CVE-2026-42505 CVSS 5.3 medium Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key…
  • CVE-2026-32283 CVSS 7.5 high If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock…
  • CVE-2025-68121 CVSS 10.0 critical During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial…
  • CVE-2025-61730 CVSS 5.3 medium During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello…
  • CVE-2025-58189 CVSS 5.3 medium When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the…