CVE-2025-61730Medium· 5.3▾ SunlitA TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.3%
Last analysed / modified upstream
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.
crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls — rated Moderate by Red Hat. Released 2025-01-01, updated 2026-09-10.
Affected:
Fixed:
No fix planned:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:7385 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:7291
Workarounds / mitigations:
Affected packages:
stdlib >= 1.25.0, < 1.25.6Patched in:
stdlib 1.25.6Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror
CVE-2026-94184High· 8.1A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support
CVE-2026-94368High· 7.1A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway
CVE-2026-92574High· 8.8A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature