Golang: stdlib: security update to 1.24.13stdlib: security update to 1.25.7stdlib: security update to 1.26.0-rc.3

critical Tenable Cloud Security Plugin ID 437577

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields
mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it
should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or
uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would
not have resumed with during the initial handshake, or cause a server to resume a session with a client
that it would not have resumed with during the initial handshake. (CVE-2025-68121)

See Also

https://pkg.go.dev/vuln/GO-2026-4337

Plugin Details

Severity: Critical

ID: 437577

Version: Revision 1.5

Type: Local

Family: Golang

Published: 2/5/2026

Updated: 3/16/2026

Risk Information

VPR

Risk Factor: High

Score: 8.1

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68121

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/5/2026

Vulnerability Publication Date: 1/22/2026

Reference Information

CVE: CVE-2025-68121