Loading HuntDB...

GHSA-89mw-w342-mqrr

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).

Related CVEs

Key Information

GHSA ID
GHSA-89mw-w342-mqrr
Published
February 28, 2023 6:30 PM
Last Modified
March 10, 2023 6:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 18, 2025 6:17 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.