Vulnerability Description
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.24.12 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/736712Patch
- https://go.dev/issue/77101Patch
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUcMailing ListRelease Notes
- https://pkg.go.dev/vuln/GO-2026-4341Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:10096
- https://access.redhat.com/errata/RHSA-2026:10104
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:10225
- https://access.redhat.com/errata/RHSA-2026:10250
- https://access.redhat.com/errata/RHSA-2026:11408
- https://access.redhat.com/errata/RHSA-2026:11414
- https://access.redhat.com/errata/RHSA-2026:11747
- https://access.redhat.com/errata/RHSA-2026:11749
- https://access.redhat.com/errata/RHSA-2026:12028
- https://access.redhat.com/errata/RHSA-2026:12029
FAQ
What is CVE-2025-61726?
CVE-2025-61726 is a vulnerability with a CVSS score of 7.5 (HIGH). The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the n...
How severe is CVE-2025-61726?
CVE-2025-61726 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-61726?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go.