Race condition in Go programming language - CVE-2025-61730

 

Race condition in Go programming language - CVE-2025-61730

Published: March 16, 2026


Vulnerability identifier: #VU124038
CSH Severity: Low
CVSS v4 BT: 0.6 [CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-61730
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to a race condition when handling multiple messages during TLS 1.3 handshake. A remote attacker with ability to inject messages during the handshake can gain access to sensitive information. 


Affected software

Go programming language
Guardium Data Security Center (GDSC)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Operator for Kubernetes Add-on

How to mitigate CVE-2025-61730

Install updates from vendor's website.

Go programming language - addressed in versions 1.24.12, 1.25.6
Guardium Data Security Center (GDSC) - update to 3.8.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 2
Splunk Operator for Kubernetes Add-on - update to 3.1.0

External References

Related Security Bulletins