Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Problem types
CWE-117: Improper Output Neutralization for Logs
Product status
Any version before 1.24.8
1.25.0 (semver) before 1.25.2
Credits
National Cyber Security Centre Finland
References
groups.google.com/g/golang-announce/c/4Emdl2iQ_bI