CVE-2025-68121: Unexpected session resumption in crypto/tls

Published Jan 17, 2026
·
Updated

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

Affected Software

9 affected components
golang/crypto
Golang Go<1.24.13
Golang Go>=1.25.0<1.25.7
Golang Go=1.26.0-rc1
Golang Go=1.26.0-rc2
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Avoid mutating a crypto/tls *Config (specifically ClientCAs and RootCAs) between the initial TLS handshake and any subsequent resumed handshake; if you need a different CA set, create a separate Config and ensure it is not changed after the session is established.

Event History

Feb 5, 2026
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-68121?

CVE-2025-68121 has a moderate severity due to potential unauthorized session resumption.

2

How do I fix CVE-2025-68121?

To fix CVE-2025-68121, update your Golang version to 1.26.0 or later, ensuring the ClientCAs and RootCAs configurations are correctly set before the handshake.

3

What versions of Golang are affected by CVE-2025-68121?

CVE-2025-68121 affects Golang versions prior to 1.26.0, including versions up to 1.24.13 and between 1.25.0 and 1.25.7.

4

What impact does CVE-2025-68121 have on application security?

CVE-2025-68121 can lead to unauthorized access during session resumption if CA configurations are modified between handshakes.

5

Is there a workaround for CVE-2025-68121?

A temporary workaround for CVE-2025-68121 is to avoid mutating the ClientCAs or RootCAs fields between handshakes until an update can be applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203