Vulnerability Description
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.24.12 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/736712Patch
- https://go.dev/issue/77101Patch
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUcRelease NotesMailing List
- https://pkg.go.dev/vuln/GO-2026-4341Vendor Advisory
FAQ
What is CVE-2025-61726?
CVE-2025-61726 is a vulnerability with a CVSS score of 7.5 (HIGH). The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the n...
How severe is CVE-2025-61726?
CVE-2025-61726 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-61726?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go.