https://seclists.org/oss-sec/2026/q1/84: CVE-2025-68121: gssion and Incomplete Fix for Go TLS Session sumption
Published Jan 17, 2026
·Updated
Affected Software
1 affected component
go Go<1.25.6, >=1.24.0
Frequently Asked Questions
1
What is the severity of CVE-2025-68121?
CVE-2025-68121 has been classified with a medium severity rating due to its potential impact on TLS session handling.
2
How do I fix CVE-2025-68121?
To fix CVE-2025-68121, you should apply the official patch provided in the Go release updates.
3
What is the impact of CVE-2025-68121 on system security?
CVE-2025-68121 could allow unauthorized users to exploit TLS sessions, leading to potential information disclosure.
4
When was CVE-2025-68121 published?
CVE-2025-68121 was published on January 17, 2026.
5
Is there any known exploitation of CVE-2025-68121?
As of now, there haven't been any publicly reported exploitations of CVE-2025-68121.