Vulnerability Description
Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.
CVSS Score
MEDIUM
References
- https://go.dev/cl/709855
- https://go.dev/issue/75672
- https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI
- https://pkg.go.dev/vuln/GO-2025-4012
- http://www.openwall.com/lists/oss-security/2025/10/08/1
FAQ
What is CVE-2025-58186?
CVE-2025-58186 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP s...
How severe is CVE-2025-58186?
CVE-2025-58186 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58186?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.