CVE-2026-42505: Golang Go
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Affected products
- Golang Go: from 1.23.0, before 1.25.12 (fixed in 1.25.12); from 1.26.0, before 1.26.5 (fixed in 1.26.5); version 1.27 only
Published 2026-07-08. Last modified 2026-09-16.