CVE-2025-61724Medium· 5.3▾ SunlitThe Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
go < 1.24.8go >= 1.25.0, < 1.25.2Upgrade past the affected range:
go 1.25.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61723High· 7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input
CVE-2025-58185Medium· 5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-58189Medium· 5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187High· 7.5Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate
CVE-2025-47912Medium· 5.3The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL
CVE-2025-58188High· 7.5Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method