← Back

CVE-2025-58181

nvd nist
Published: Nov 19, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Affected (1)

Products: Golang: Crypto
1 product
Crypto
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.45.0

References (4)

Source: security@golang.org
Patch
Source: security@golang.org
Issue Tracking
Source: security@golang.org
Mailing List
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.