Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 29 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang go
|
|
| Weaknesses | CWE-532 | |
| CPEs | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Golang go
|
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang crypto |
|
| Vendors & Products |
Golang
Golang crypto |
Fri, 31 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped. | |
| Title | ALPN negotiation error contains attacker controlled information in crypto/tls | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-11-04T21:13:39.428Z
Reserved: 2025-08-27T14:50:58.692Z
Link: CVE-2025-58189
Updated: 2025-11-04T21:13:39.428Z
Status : Analyzed
Published: 2025-10-29T23:16:19.833
Modified: 2026-01-29T15:49:24.543
Link: CVE-2025-58189
OpenCVE Enrichment
Updated: 2025-10-31T10:14:07Z