CVE-2026-42505
ADVISORY - debianSummary
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
- golang-1.27 1.27~rc2-1
- golang-1.26 1.26.5-1
- golang-1.25 1.25.12-1
- golang-1.24 [trixie] - golang-1.24 (Minor issue)
- golang-1.19 [bookworm] - golang-1.19 (crypto/tls client ECH introduced in Go 1.23; absent in 1.19)
- golang-1.15 (Vulnerable code introduced later) crypto/tls client Encrypted Client Hello introduced in Go 1.23 (issue #63369) https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc https://github.com/golang/go/issues/79282 Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5) Fixed by: https://github.com/golang/go/commit/fc9f821bb660c1dcb9e57868b62f62bf3afb5842 (go1.25.12)
EPSS Scoreโ : 0.00382 (0.316)
Common Weakness Enumeration (CWE)
ADVISORY - redhat
Insertion of Sensitive Information Into Sent Data
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in