CVE Vulnerabilities

CVE-2025-58189

Insertion of Sensitive Information into Log File

Published: Oct 29, 2025 | Modified: Jan 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.24.8 (excluding)
GoGolang1.25.0 (including)1.25.2 (excluding)
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*

Potential Mitigations

References