CVE-2022-30629 - CVE House
Back to Database
Status published Unknown CVE-2022-30629

Session tickets lack random ticket_age_add in crypto/tls

Vulnerability Description

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-30629

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Github user @nervuri

Affected Vendor

Go standard library

View all reports →

Affected Software

crypto/tls
Vulnerable Versions:
0, 1.18.0-0

Timeline

Official Publish: August 9th, 2022
Last Modified: March 6th, 2026
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.