CVE-2025-58189: Golang Go

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Affected products

  • Golang Go: before 1.24.8 (fixed in 1.24.8); from 1.25.0, before 1.25.2 (fixed in 1.25.2)

Published 2025-10-29. Last modified 2026-10-08.