CVE-2022-32189High· 7.5▾ TwilightA too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.6%
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
go < 1.17.13go >= 1.18.0, < 1.18.5Upgrade past the affected range:
go 1.18.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61724Medium· 5.3The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines
CVE-2025-61723High· 7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input
CVE-2025-58189Medium· 5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187High· 7.5Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate
CVE-2025-68120Medium· 5.4To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
CVE-2025-58185Medium· 5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.