← Voltar para CVEs
CVE-2025-61730
MEDIUM5.3
Descricao
During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.
Detalhes CVE
Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/28/2026
Ultima modificacao2/3/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
golang:go
Referencias
https://go.dev/cl/724120(security@golang.org)
https://go.dev/issue/76443(security@golang.org)
https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc(security@golang.org)
https://pkg.go.dev/vuln/GO-2026-4340(security@golang.org)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.