CVE-2025-68121Patch(golang / go)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch golang go systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

4.3/ 10 priority

Sources & remediation

Exploit / PoC references
Weakness type (CWE)
CWE-295

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 19 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 6 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-11); latest day: 1
  • 19 total mentions across 10 days

Affected systems

Vendors
Products
go

1 version affected across 1 product

Deep dive

Activity timeline19 mentions / 10d
01234Mentions · 2026-02-04: 2Mentions · 2026-02-05: 3Mentions · 2026-02-08: 1Mentions · 2026-02-11: 3Mentions · 2026-02-12: 2Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-23: 1Mentions · 2026-03-11: 4Mentions · 2026-04-27: 1Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 4Patch / Workaround · 2026-04-27: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 102-0402-0502-0802-1102-1202-1302-1402-2303-1104-27
Signal classification4 categories
Patch
1052.6%
General
526.3%
Disclosure
315.8%
Active Exploitation
15.3%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-042
Patch2
2026-02-053
Disclosure2General1
2026-02-081
Patch1
2026-02-113
Disclosure1General1Patch1
2026-02-122
Active Exploitation1General1
2026-02-131
General1
2026-02-141
General1
2026-02-231
Patch1
2026-03-114
Patch4
2026-04-271
Patch1
Full discourse19 posts
  • Go@golang
    Patch

    🥳 Go 1.26 Release Candidate 3 is released! 🔐 Security: Includes an update for crypto/tls (CVE-2025-68121). 🏃‍♂️ Run it in dev! Run it in prod! File bugs! https://go.dev/issue/new 📢 Announcement: https://groups.google.com/g/golang-announce/c/1_lL9W-3AOI/m/ya7qa8k9AQAJ ⬇️ Download: https://go.dev/dl/#go1.26rc3 #golang https://t.co/Zqwig60LB8

    Post summary

    Go 1.26 Release Candidate 3 includes a patch for CVE‑2025‑68121 affecting crypto/tls, addressing the vulnerability.

    46324462321.8K
    206.6K followersView on X
  • Go@golang
    Patch

    🎉 Go 1.25.7 and 1.24.13 are released! 🔐 Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). 🗣 Announcement: https://groups.google.com/g/golang-announce/c/K09ubi9FQFk/m/oQiZUMk9AQAJ 📦 Download: https://go.dev/dl/#go1.25.7 #golang https://t.co/NnF8ayxKrK

    Post summary

    Go 1.25.7 and 1.24.13 releases include security fixes for CVE-2025-61732 and CVE-2025-68121, with official vendor advisories and download links provided.

    34823431816.7K
    206.6K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Go 1.25.7, 1.24.13 fix 2 CVEs https://www.openwall.com/lists/oss-security/2026/02/07/2 CVE-2025-61732: cmd/cgo: Discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the cgo binary CVE-2025-68121: crypto/tls: Unexpected session resumption when using Config.GetConfigForClient

    Post summary

    Go 1.25.7 and 1.24.13 have been released to fix CVE-2025-61732 and CVE-2025-68121, addressing code smuggling via cgo comment parsing and an unexpected TLS session resumption bug, respectively. The post confirms the availability of the patches and provides brief technical details of each vulnerability.

    01071576
    4.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A security vulnerability (CVE-2025-68121) in `golang` `crypto/tls` may lead to unexpected session resumption. Developers should review `golang` deployments and consider updating. #golang #TLS #infosec https://www.pulsepatch.io/posts/cve-2025-68121-golang-unexpected-tls-session-resumption

    Post summary

    The post announces CVE-2025-68121, a TLS session resumption flaw in Go's crypto/tls library, and urges developers to review their deployments and apply updates.

    6000097
    1 followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The text enumerates a set of CVEs being addressed by security fixes, suggesting a patch release but providing no technical or exploit details.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The note announces a security patch for apigee‑hybrid‑cassandra‑client that addresses a list of CVEs.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    A concise notice lists multiple CVEs and states that security fixes are available for apigee-connect-agent.

    1000097
    1.8K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 42% of vulnerabilities from past week, CVE-2025-68121 has 14 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post merely highlights that CVE‑2025‑68121 has garnered a high number of articles, offering no technical, exploit, or mitigation details.

    0001068
    73 followersView on X
  • Soo Yoon | FailSafe Ecosystem@sooyoon_eth
    Disclosure

    @pulsepatchio golang TLS vuln is wild. CVE-2025-68121 + unexpected session resumption = classic case of crypto libs betraying assumptions. how many teams gonna patch before this gets weaponized?

    Post summary

    The tweet announces a Golang TLS CVE (CVE-2025-68121) involving unexpected session resumption, urging teams to patch before potential weaponization.

    0010065
    23.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake,… https://www.cve.org/CVERecord?id=CVE-2025-68121

    Post summary

    The text discloses CVE‑2025‑68121, noting a vulnerability in Go's crypto/tls during session resumption when Config fields are mutated between handshakes.

    00010381
    56.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-1861 2 - CVE-2004-0200 3 - CVE-2026-20026 4 - CVE-2025-46298 5 - CVE-2025-68121 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief post listing five trending CVEs with no additional context or details.

    00010191
    1.7K followersView on X
  • Mario Fahlandt 🦊@mfahlandt
    Patch

    Last Week in Cloud Native: ⚙️ Kubernetes v1.36 released: User Namespaces & Kubelet API Auth GA. Kyverno v1.16.4 fixed CVE-2025-68121. cert-manager v1.19.5 resolved CVEs. Full breakdown: https://www.lwcn.dev/newsletter/2026-week-18/

    Post summary

    The post reports that Kyverno release v1.16.4 includes a fix for CVE‑2025‑68121, indicating a patch availability.

    00000547
    501 followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The text announces that the apigee-stackdriver-logging-agent update contains patches for a list of CVEs, indicating a fix release.

    00000116
    1.8K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-68121 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/401 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE-2025-68121, indicating the vulnerability has been addressed.

    0000040
    30 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 84% of vulnerabilities from past week, CVE-2025-68121 has 16 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE‑2025‑68121 has a high volume of coverage and links to an external source for more information, but offers no technical, exploit, or patch details.

    0000059
    73 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 70% of vulnerabilities from past week, CVE-2025-68121 has 16 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE-2025-68121 has 16 articles published, but it does not provide any technical, PoC, exploitation, patch, or debunking information.

    0000056
    73 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 56% of vulnerabilities from past week, CVE-2025-68121 has 14 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet references CVE-2025-68121 and links to a website but gives no details on exploitation, mitigations, or technical aspects.

    0000054
    73 followersView on X
  • Soo Yoon | FailSafe Ecosystem@sooyoon_eth
    Active Exploitation

    @pulsepatchio CVE-2025-68121 in golang crypto/tls is wild. unexpected session resumption = man-in-middle vectors. any crypto project using golang TLS should patch asap

    Post summary

    CVE-2025-68121 in Golang’s TLS is actively exploited, enabling man‑in‑the‑middle attacks, and users should patch immediately.

    0000061
    23.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-68121 Session Resumption Bypass in Go crypto/tls Config.GetConf... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-68121 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE‑2025‑68121, a session resumption bypass in Go’s crypto/tls, but offers only a brief title and a link to details, with no exploit, PoC, or mitigation information.

    0000083
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---
Appgolanggo1.26.0--
Appgolanggo1.26.0--

Explore more