We found results for “”
CVE-2025-58187
Good to know:
Date: October 7, 2025
In Go before 1.24.8 and 1.25.x before 1.25.2, Due to the design of the name constraint checking algorithm, the processing time of some inputs scales non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
Severity Score
Severity Score
Weakness Type (CWE)
Improper Validation of Integrity Check Value
CWE-354Top Fix
Upgrade Version
Upgrade to version https://github.com/golang/go.git - go1.24.8;https://github.com/golang/go.git - go1.25.2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


