CVE-2025-58189: ALPN negotiation error contains attacker controlled information in crypto/tls
ALPN negotiation error contains attacker controlled information in crypto/tls
Other sources
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58189?
CVE-2025-58189 has been classified as a medium severity vulnerability due to potential exposure of sensitive information during ALPN negotiation.
How do I fix CVE-2025-58189?
To remediate CVE-2025-58189, you should update to the latest version of the affected software that addresses this vulnerability.
What products are affected by CVE-2025-58189?
CVE-2025-58189 impacts various Microsoft products, including multiple versions of TensorFlow, GCC, and Go.
What type of information is exposed in CVE-2025-58189?
CVE-2025-58189 exposes attacker-controlled information in the error messages during ALPN handshake failures.
Is CVE-2025-58189 a client-side or server-side vulnerability?
CVE-2025-58189 can be exploited during the server-side ALPN negotiation process.