{"id":"GO-2023-2044","summary":"Panic when processing post-handshake message on QUIC connections in crypto/tls","details":"Processing an incomplete post-handshake message for a QUIC connection can cause a panic.","aliases":["BIT-golang-2023-39321","CVE-2023-39321"],"modified":"2026-02-04T02:46:26.184665Z","published":"2023-09-07T16:12:03Z","related":["CGA-86qj-5grc-8pm6"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2023-2044","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://go.dev/issue/62266"},{"type":"FIX","url":"https://go.dev/cl/523039"},{"type":"WEB","url":"https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ"}],"affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.21.0-0"},{"fixed":"1.21.1"}]}],"ecosystem_specific":{"imports":[{"path":"crypto/tls","symbols":["QUICConn.HandleData"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2044.json"}}],"schema_version":"1.7.3","credits":[{"name":"Marten Seemann"}]}