CVE-2025-22874

Published Jun 11, 2025

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-22874 affects Google Go's crypto-x509 component, specifically the VerifyOptions.KeyUsages function. This vulnerability involves improper certificate validation due to manipulation with an unknown input. The vulnerability lies in the product's failure to properly validate certificates, potentially impacting integrity. It can be exploited remotely without authentication, though exploitation is considered difficult. The vulnerability is addressed in versions 1.23.10 and 1.24.4 of Google Go.

Description
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
Source
security@golang.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity
HIGH

Social media

Hype score
Not currently trending