CVE-2025-58187High· 7.5▾ TwilightDue to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
go < 1.24.9go >= 1.25.0, < 1.25.3Upgrade past the affected range:
go 1.25.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61724Medium· 5.3The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines
CVE-2025-61723High· 7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input
CVE-2025-58189Medium· 5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58185Medium· 5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912Medium· 5.3The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL
CVE-2025-58188High· 7.5Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method