
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61730 is a TLS 1.3 handshake encryption level boundary flaw in Go's crypto/tls standard library package. During a TLS 1.3 handshake, if multiple messages are sent in records that span encryption level boundaries (e.g., Client Hello and Encrypted Extensions), subsequent messages may be processed before the encryption level changes, potentially enabling minor information disclosure. The vulnerability affects Go versions prior to 1.24.12 and versions 1.25.0 through 1.25.5 (prior to 1.25.6). It carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Go Vuln DB).
The root cause is classified as CWE-940 (Improper Verification of Source of a Communication Channel), where the Go TLS 1.3 implementation fails to enforce strict encryption level transitions when multiple handshake messages are coalesced into a single TLS record spanning an encryption boundary. An attacker positioned on the local network segment can inject messages during the handshake before the expected encryption upgrade takes effect, causing the peer to process those messages under the wrong encryption context. Exploitation requires network-local positioning (not remote) and the ability to inject traffic during an active TLS 1.3 handshake. The issue is tracked upstream as Go issue #76443 and fixed in changelist 724120 (Go Issue, Go CL, Go Vuln DB).
Successful exploitation results in minor information disclosure during the TLS 1.3 handshake, as handshake messages may be processed at an incorrect (lower) encryption level. There is no impact on integrity or availability, and the confidentiality impact is assessed as low. The vulnerability does not enable remote code execution, credential theft, or session decryption of application data, but could expose handshake metadata to a network-local attacker (Red Hat Advisory, Go Vuln DB).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-61730. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. Exploitation requires network-local positioning and the ability to inject traffic during an active TLS 1.3 handshake, significantly limiting the attacker pool (Go Vuln DB, Red Hat Advisory).
The Go project has released fixed versions addressing this vulnerability: Go 1.24.12 and Go 1.25.6. Organizations using affected Go versions (any version before 1.24.12, or 1.25.0–1.25.5) should upgrade to the patched releases. IBM has also issued patches for affected products including Data Virtualization on IBM Software Hub, IBM Db2 on Cloud Pak for Data, IBM Business Automation Insights, IBM Observability with Instana (OnPrem), and IBM watsonx Orchestrate (Go CL, IBM Data Virtualization, IBM Db2, IBM BAI, IBM Instana). No configuration-based workaround is available; upgrading the Go runtime is the only remediation.
The Go security team disclosed the vulnerability via the golang-announce mailing list alongside the Go 1.24.12 and 1.25.6 release announcements. Several security news outlets including CyberSecurityNews, GBHackers, and HealSecurity covered the Go patch releases, though coverage primarily focused on co-disclosed DoS and memory exhaustion vulnerabilities rather than CVE-2025-61730 specifically. The vulnerability was also discussed briefly on Reddit's CVEWatch community and noted by security researchers on Mastodon (golang-announce, oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."