CVE-2025-61730: Golang Go

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.

Affected products

  • Golang Go: before 1.24.12 (fixed in 1.24.12); from 1.25.0, before 1.25.6 (fixed in 1.25.6)

Published 2026-01-28. Last modified 2026-06-17.