User Impersonation Affecting std/crypto/tls package, versions >=1.1.0-0 <1.3.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.38% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-STDCRYPTOTLS-14565452
  • published6 Jan 2026
  • disclosed25 May 2022
  • creditGo Team

Introduced: 25 May 2022

CVE-2014-7189  (opens in a new tab)
CWE-290  (opens in a new tab)

How to fix?

Upgrade std/crypto/tls to version 1.3.2 or higher.

Overview

std/crypto/tls is a Go standard library package std/crypto/tls

Affected versions of this package are vulnerable to User Impersonation.

Go Vulnerability Report:
in the crypto/tls process when SessionTicketsDisabled is enabled. An attacker can impersonate clients by spoofing client certificates through a man-in-the-middle attack. This is only exploitable if TLS client authentication using certificates is enabled and SessionTicketsDisabled is explicitly set to true in the configuration.

CVSS Base Scores

version 4.0
version 3.1