[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-42505":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T17:19:26.604Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":55,"aliases":56,"duplicate_of":9,"upstream":59,"downstream":60,"duplicates":103,"related":104,"reserved_at":9,"published_at":125,"modified_at":126,"state":127,"summary":128,"references_raw":135,"kevs":156,"epss":9,"epss_history":157,"metrics":158,"affected":164},"CVE-2026-42505","Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-201","Insertion of Sensitive Information Into Sent Data","The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.","weakness","Draft","Base",[19,23,27,31,35,39,43,47,51],{"id":20,"name":21,"techniques":22},"CAPEC-12","Choosing Message Identifier",[],{"id":24,"name":25,"techniques":26},"CAPEC-217","Exploiting Incorrectly Configured SSL/TLS",[],{"id":28,"name":29,"techniques":30},"CAPEC-612","WiFi MAC Address Tracking",[],{"id":32,"name":33,"techniques":34},"CAPEC-613","WiFi SSID Tracking",[],{"id":36,"name":37,"techniques":38},"CAPEC-618","Cellular Broadcast Message Request",[],{"id":40,"name":41,"techniques":42},"CAPEC-619","Signal Strength Tracking",[],{"id":44,"name":45,"techniques":46},"CAPEC-621","Analysis of Packet Timing and Sizes",[],{"id":48,"name":49,"techniques":50},"CAPEC-622","Electromagnetic Side-Channel Attack",[],{"id":52,"name":53,"techniques":54},"CAPEC-623","Compromising Emanations Attack",[],[],[57,58],"GO-2026-5856","BIT-golang-2026-42505",[],[61,63,65,67,69,71,73,75,77,79,81,83,85,87,89,91,93,95,97,99,101],{"_key":62},"SUSE-SU-2026:2817-1",{"_key":64},"SUSE-SU-2026:2818-1",{"_key":66},"OPENSUSE-SU-2026:11212-1",{"_key":68},"OPENSUSE-SU-2026:11216-1",{"_key":70},"OPENSUSE-SU-2026:11232-1",{"_key":72},"MGASA-2026-0276",{"_key":74},"SUSE-SU-2026:22638-1",{"_key":76},"SUSE-SU-2026:22641-1",{"_key":78},"SUSE-SU-2026:22643-1",{"_key":80},"SUSE-SU-2026:22656-1",{"_key":82},"SUSE-SU-2026:3046-1",{"_key":84},"SUSE-SU-2026:3047-1",{"_key":86},"SUSE-SU-2026:3102-1",{"_key":88},"RHSA-2026:36477",{"_key":90},"RHSA-2026:36510",{"_key":92},"UBUNTU-CVE-2026-42505",{"_key":94},"DEBIAN-CVE-2026-42505",{"_key":96},"OPENSUSE-SU-2026:21319-1",{"_key":98},"OPENSUSE-SU-2026:21321-1",{"_key":100},"OPENSUSE-SU-2026:21324-1",{"_key":102},"OPENSUSE-SU-2026:21341-1",[],[105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123],{"_key":62},{"_key":64},{"_key":66},{"_key":68},{"_key":70},{"_key":74},{"_key":76},{"_key":78},{"_key":80},{"_key":82},{"_key":84},{"_key":86},{"_key":88},{"_key":90},{"_key":96},{"_key":98},{"_key":100},{"_key":102},{"_key":124},"CGA-C2QP-QCHH-369W","2026-07-08T15:46:33.407Z","2026-07-08T19:38:17.603Z","PUBLISHED",{"cisa_kev":129,"cisa_ransomware":129,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":130,"severity_score":131,"severity_version":132,"severity_source":133,"severity_vector":134,"severity_status":127},false,"medium",5.3,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",[136,142,147,152],{"url":137,"sources":138,"tags":140},"https://go.dev/cl/775960",[133,139],"osv_go",[141],"FIX",{"url":143,"sources":144,"tags":145},"https://go.dev/issue/79282",[133,139],[146],"REPORT",{"url":148,"sources":149,"tags":150},"https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc",[133,139],[151],"WEB",{"url":153,"sources":154,"tags":155},"https://pkg.go.dev/vuln/GO-2026-5856",[133],[],[],[],[159],{"source":133,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":160,"cvss_v4_0":9},{"baseScore":131,"baseSeverity":161,"vectorString":134,"impactScore":162,"exploitabilityScore":163},"MEDIUM",2.3,10,[165,184],{"ecosystem":9,"name":166,"vendor":167,"product":166,"cpe_part":168,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":169},"crypto/tls","go standard library","a",[170,175,180],{"version":171,"is_range":172,"range_type":133,"version_start":9,"version_start_type":9,"version_end":173,"version_end_type":174,"fixed_in":9},"\u003C 1.25.12",true,"1.25.12","excluding",{"version":176,"is_range":172,"range_type":133,"version_start":177,"version_start_type":178,"version_end":179,"version_end_type":174,"fixed_in":9},">= 1.26.0-0, \u003C 1.26.5","1.26.0-0","including","1.26.5",{"version":181,"is_range":172,"range_type":133,"version_start":182,"version_start_type":178,"version_end":183,"version_end_type":174,"fixed_in":9},">= 1.27.0-0, \u003C 1.27.0-rc.2","1.27.0-0","1.27.0-rc.2",{"ecosystem":185,"name":186,"vendor":185,"product":186,"cpe_part":9,"purl_type":187,"purl_namespace":9,"purl_name":186,"source":9,"versions":188},"Go","stdlib","golang",[189],{"version":190,"is_range":172,"range_type":191,"version_start":182,"version_start_type":178,"version_end":183,"version_end_type":174,"fixed_in":9},"gte1_27_0_0_lt1_27_0_rc_2","semver"]