Vulnerability Description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Crypto | < 0.45.0 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/721961Patch
- https://go.dev/issue/76363Issue Tracking
- https://groups.google.com/g/golang-announce/c/w-oX3UxNcZAMailing List
- https://pkg.go.dev/vuln/GO-2025-4134Vendor Advisory
FAQ
What is CVE-2025-58181?
CVE-2025-58181 is a vulnerability with a CVSS score of 5.3 (MEDIUM). SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
How severe is CVE-2025-58181?
CVE-2025-58181 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58181?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Crypto.