Information Disclosure Vulnerability in Go Programming Language
CVE-2025-61730
What is CVE-2025-61730?
During the TLS 1.3 handshake process in the Go programming language, there exists a scenario where multiple messages may be sent in records that cross encryption level boundaries, such as the Client Hello and Encrypted Extensions messages. This mishandling can lead to minor information disclosure if an attacker on the same network is able to inject messages during the handshake process. The vulnerability highlights the importance of robust encryption level management in secure communications, emphasizing the necessity for developers to ensure strict adherence to protocols to safeguard data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
crypto/tls 0 < 1.24.12
crypto/tls 1.25.0 < 1.25.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
