CVE-2025-58189

MEDIUM

GO < 1.24.8 - Log Information Exposure

Title source: rule

Description

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 0.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-532
Status published

Affected Products (1)

golang/go < 1.24.8

Timeline

Published Oct 29, 2025
Tracked Since Feb 18, 2026