https://seclists.org/oss-sec/2026/q1/83: CVE-2025-68121: gssion and Incomplete Fix for Go TLS Session sumption
Published Jan 17, 2026
·Updated
Affected Software
1 affected component
golang/go>=1.24.0<=1.25.6
Frequently Asked Questions
1
What is the severity of CVE-2025-68121?
CVE-2025-68121 is considered a critical vulnerability affecting the Go programming language.
2
What does CVE-2025-68121 involve?
CVE-2025-68121 involves an incomplete fix for TLS session assumption issues in Go, potentially impacting secure communications.
3
How do I fix CVE-2025-68121?
To mitigate CVE-2025-68121, users should update to the latest version of Go once a proper fix is released.
4
Which versions of Go are affected by CVE-2025-68121?
CVE-2025-68121 impacts Go version 1.25.6 and 1.24.x.
5
What should I do if I am using a vulnerable version of Go due to CVE-2025-68121?
If using a vulnerable version of Go, it is recommended to follow security announcements from the Go team for guidance and updates.