HomeGolangCVE-2025-68121

CVE-2025-68121

CRITICAL
10.0CVSS
Published: 2026-02-05
Updated: 2026-02-10
AI Analysis

Description

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-295

Metadata

Primary Vendor
GOLANG
Published
2/5/2026
Last Modified
2/10/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

golang : gogolang : gogolang : gogolang : go

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief