{"id":"AZL-105164","summary":"CVE-2021-34558 affecting package golang 1.26.7-1","details":"The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.","modified":"2026-10-01T14:15:48.593657225Z","published":"2021-07-15T14:15:19Z","upstream":["CVE-2021-34558"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-34558"}],"affected":[{"package":{"name":"golang","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/golang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.26.7-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105164.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}