216.73.217.22

CVE-2025-61729

· Published 02/12/2025 19:15 · Modified 19/12/2025 18:25

Labels: CVE-2025-61729 2025-12-02CVE-2025-61729CWE-295[email protected]

Essential information

Published
02/12/2025 19:15
Modified
19/12/2025 18:25
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
golang / go cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
golang / go cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

References