← Back

CVE-2025-61729

nvd nist
Published: Dec 2, 2025Modified: Dec 19, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

Affected (2)

Products: Golang: Go
1 product
Go
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Golang
Before 1.24.11
From 1.25.0 to 1.25.5

References (4)

Source: security@golang.org
Patch
Source: security@golang.org
Issue TrackingPatch
Source: security@golang.org
Mailing ListRelease Notes
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.