---
id: CVE-2025-59530
title: >-
  github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE
  Frame (CVE-2025-59530)
summary: >-
  A denial of service flaw has been discovered in the quic-go golang library. A
  misbehaving or malicious server can cause a denial-of-service (DoS) attack on
  the quic-go client by triggering an assertion failure, leading to a process
  crash. …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cvssSource: vendor
cwe: CWE-617
vendor: Red Hat
product: Red Hat Ansible Automation Platform 2.5 for RHEL 8
affected:
  - openshift_service_mesh 2
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - openshift_dev_spaces
  - ansible_automation_platform_2_4_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_4_for_rhel 9
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - advanced_cluster_management_for_kubernetes 2.13
  - advanced_cluster_management_for_kubernetes 2.14
  - advanced_cluster_management_for_kubernetes 2.15
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
patched:
  - ansible_automation_platform_2_4_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_4_for_rhel 9
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - advanced_cluster_management_for_kubernetes 2.13
  - advanced_cluster_management_for_kubernetes 2.14
  - advanced_cluster_management_for_kubernetes 2.15
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
published: '2025-10-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T01:33:57+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59530.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59530.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-59530'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2403125'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-59530'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59530'
  - url: 'https://github.com/quic-go/quic-go/blob/v0.55.0/connection.go#L2682-L2685'
  - url: 'https://github.com/quic-go/quic-go/pull/5354'
  - url: 'https://github.com/quic-go/quic-go/security/advisories/GHSA-47m2-4cr7-mhcw'
  - url: 'https://access.redhat.com/errata/RHSA-2025:21706'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23069'
  - url: 'https://access.redhat.com/errata/RHSA-2025:21768'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36873'
  - url: 'https://access.redhat.com/errata/RHSA-2025:21892'
  - url: 'https://access.redhat.com/errata/RHSA-2025:22784'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23131'
  - url: 'https://access.redhat.com/errata/RHSA-2025:21775'
  - url: >-
      https://github.com/quic-go/quic-go/commit/bc5bccf10fd02728eef150683eb4dfaa5c0e749c
  - url: >-
      https://github.com/quic-go/quic-go/commit/ce7c9ea8834b9d2ed79efa9269467f02c0895d42
  - url: 'https://github.com/quic-go/quic-go'
  - url: 'https://pkg.go.dev/vuln/GO-2025-4017'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
  - score-dispute
epss: 0.00465
epssPercentile: 0.3764
aliases:
  - GHSA-47m2-4cr7-mhcw
  - GO-2025-4017
ecosystem: go
scores:
  vendor: 5.3
  osv: 7.5
ingestedAt: '2026-08-07T19:14:15.704Z'
---

## Overview

A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations.

## Vendor advisories

- **RHSA-2025:21706** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9 · released 2025-11-18 · [advisory](https://access.redhat.com/errata/RHSA-2025:21706)
- **RHSA-2025:23069** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23069)
- **RHSA-2025:21768** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2025-11-19 · [advisory](https://access.redhat.com/errata/RHSA-2025:21768)
- **RHSA-2026:36873** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36873)
- **RHSA-2025:21892** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2025-11-20 · [advisory](https://access.redhat.com/errata/RHSA-2025:21892)
- **RHSA-2025:22784** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2025-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2025:22784)
- **RHSA-2025:23131** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2025-12-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:23131)
- **RHSA-2025:21775** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2025-11-19 · [advisory](https://access.redhat.com/errata/RHSA-2025:21775)
- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, OpenShift Service Mesh 2, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Dev Spaces · updated 2026-09-26 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59530.json)

**github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame** — rated Moderate by Red Hat. Released 2025-10-10, updated 2026-09-26.

Affected:

- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Dev Spaces

Fixed:

- Red Hat Ansible Automation Platform 2.4 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6

No fix planned:

- Red Hat Advanced Cluster Management for Kubernetes 2
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Dev Spaces

Not affected:

- Red Hat Ansible Automation Platform 2.4 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.4 for RHEL 9
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6

## Remediation

Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:21706
Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:23069
Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:21768

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-59530)

Affected packages:

- `github.com/quic-go/quic-go < 0.49.1`
- `github.com/quic-go/quic-go >= 0.50.0, < 0.54.1`

Patched in:

- `github.com/quic-go/quic-go 0.49.1`
- `github.com/quic-go/quic-go 0.54.1`

Source: https://osv.dev/vulnerability/GHSA-47m2-4cr7-mhcw
