Loading HuntDB...

GHSA-j55j-52j7-vq87

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Related CVEs

Key Information

GHSA ID
GHSA-j55j-52j7-vq87
Published
August 11, 2022 12:00 AM
Last Modified
August 17, 2022 12:00 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 17, 2025 2:40 PM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.