PT-2025-42742 · Unknown+4 · Golang-1.15+5
CVE-2025-58189
·
Published
2025-01-01
·
Updated
2026-08-24
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Go versions prior to 1.24.9-alt1
Fedora 42
Fedora 43
Description
The issue involves a flaw in the crypto/tls component of the Go programming language. Specifically, when the
Conn.Handshake process fails during ALPN (Application-Layer Protocol Negotiation), the resulting error message includes attacker-controlled data—the ALPN protocols proposed by the client—without proper sanitization. This can lead to information disclosure. The vulnerability also affects logging, as insufficient filtering or escaping of log files allows remote attackers to potentially inject or manipulate log entries. Multiple reports indicate that the vulnerability affects the Cloud SQL Proxy and is addressed in updates for Fedora.Recommendations
Upgrade Go to version 1.24.9-alt1 or later.
Update kustomize to version 5.8.0.
Rebuild k9s to mitigate the risk.
Exploit
Fix
DoS
Special Elements Injection
Improper Neutralization
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Red Os
Suse
Golang-1.15
Golang-1.19