CVE-2026-42505 affecting package golang for versions less than 1.25.12-1
Details
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.