CVE-2025-58189
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
- Published Oct 29, 2025
- CVSS 5.3 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available