CVE Vulnerabilities

CVE-2025-68121

Improper Certificate Validation

Published: Feb 05, 2026 | Modified: Feb 20, 2026
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.24.13 (excluding)
GoGolang1.25.0 (including)1.25.7 (excluding)
GoGolang1.26.0-rc1 (including)1.26.0-rc1 (including)
GoGolang1.26.0-rc2 (including)1.26.0-rc2 (including)
Cryostat 4 on RHEL 9RedHatcryostat/cryostat-storage-rhel9:4.1.1-3*
Red Hat Enterprise Linux 10RedHatgolang-0:1.25.7-1.el10_1*
Red Hat Enterprise Linux 10RedHatgrafana-0:10.2.6-22.el10_1*
Red Hat Enterprise Linux 10RedHatgrafana-pcp-0:5.3.0-2.el10_1*
Red Hat Enterprise Linux 10RedHatgolang-github-openprinting-ipp-usb-0:0.9.27-5.el10_1*
Red Hat Enterprise Linux 10RedHatbuildah-2:1.41.8-2.el10_1*
Red Hat Enterprise Linux 10RedHatpodman-7:5.6.0-12.el10_1*
Red Hat Enterprise Linux 10RedHatskopeo-2:1.20.0-3.el10_1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatgolang-0:1.25.7-1.el10_0*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8100020260212045823.a3795dee*
Red Hat Enterprise Linux 8RedHatgrafana-pcp-0:5.1.1-12.el8_10*
Red Hat Enterprise Linux 8RedHatgrafana-0:9.2.10-28.el8_10*
Red Hat Enterprise Linux 9RedHatgolang-0:1.25.7-1.el9_7*
Red Hat Enterprise Linux 9RedHatgrafana-0:10.2.6-18.el9_7*
Red Hat Enterprise Linux 9RedHatgrafana-pcp-0:5.1.1-12.el9_7*
Red Hat Enterprise Linux 9RedHatrunc-4:1.4.0-2.el9_7*
Red Hat Enterprise Linux 9RedHatbuildah-2:1.41.8-2.el9_7*
Red Hat Enterprise Linux 9RedHatpodman-6:5.6.0-14.el9_7*
Red Hat Enterprise Linux 9RedHatskopeo-2:1.20.0-3.el9_7*
Red Hat Enterprise Linux 9RedHatcontainernetworking-plugins-1:1.7.1-3.el9_7*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatgolang-0:1.25.7-1.el9_6*
Red Hat Developer Hub 1.8RedHatrhdh/rhdh-rhel9-operator:sha256:6e76191bf1d5afa5ee76330bf6c8860889e0d10661e4633dbb50254ebacfccd9*

Potential Mitigations

References