AI description
CVE-2025-47907 refers to a security vulnerability found in Go versions 1.24.6 and 1.23.12. This vulnerability is located in the `database/sql` package. Specifically, if a query is cancelled (e.g., by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows, it can lead to unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.
- Description
- Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.
- Source
- security@golang.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7
- Impact score
- 4.7
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity
- HIGH
- Hype score
- Not currently trending
π HIGH (CVSS 7.0) β CVE-2025-47907 Published: 2025-08-07 database/sql: Postgres Scan Race Condition 𧬠CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L #CVE #CyberSecurity #InfoSec #Vulnerability ββββββββββββββ #CVE2026 The vuln
@CVE2026COIN
22 Jun 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
β οΈ AtenΓ§Γ£o, administradores openSUSE! A CVE-2025-47907 no azure-storage-azcopy pode corromper silenciosamente seus dados durante transfers para o Azure. Saiba mais- > https://t.co/9meCm7FtbH #openSUSE https://t.co/u4Bgjlep7v
@Cezar_H_Linux
20 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
π΄ Go Standard Library, Race Condition, #CVE-2025-47907 (High) https://t.co/efXsFGwUet
@dailycve
5 Jan 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: Patch Go 1.24 now! CVE-2025-47906 (CVSS 4.0) & CVE-2025-47907 (CVSS 7.0) impact 35+ SUSE distros (Leap/SLES/SAP/HPC). Exploits allow path hijacking & DB corruption. Read more:π https://t.co/7SlwnaLWqA #Security #SUSE https://t.co/4a7foJYyrP
@Cezar_H_Linux
12 Aug 2025
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
π¨ ALERT: CVE-2025-47907 (CVSS 7.0) in Go 1.23 lets attackers corrupt database results. Patch #SUSE Linux, SAP, HPC systems IMMEDIATELY. Read more: π https://t.co/ddFLtCUsEz #Security https://t.co/PEZMaEQorZ
@Cezar_H_Linux
12 Aug 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-47907 Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected β¦ https://t.co/jFQnxBPryZ
@CVEnew
7 Aug 2025
162 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
π Go 1.24.6 and 1.23.12 are released! π Security: Includes security fixes for os/exec (CVE-2025-47906) and database/sql (CVE-2025-47907). π’ Announcement: https://t.co/o2LJKjXYvP β¬οΈ Download: https://t.co/ffHEmehO2d #golang https://t.co/4MF9a7DSL7
@golang
6 Aug 2025
17624 Impressions
84 Retweets
350 Likes
19 Bookmarks
0 Replies
2 Quotes