- Description
- Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
- Source
- security@golang.org
- NVD status
- Analyzed
- Products
- go
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-407
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos VMware ❗ CVE-2025-61725 ❗ CVE-2025-58188 ❗ CVE-2025-58187 ➡️ Más info: https://t.co/f2QzldWdbF https://t.co/vkGw6I6sgQ
@CERTpy
15 Jan 2026
98 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-58187 Due to the design of the name constraint checking algorithm, the processing time of some inputs scals non-linearly with respect to the size of the certificate. This a… https://t.co/qtn9lTVp3l
@CVEnew
29 Oct 2025
360 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C89AAA9E-5381-4C85-836A-04FD377BA155",
"versionEndExcluding": "1.24.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "37360D5C-FBAB-40DE-8397-F84D46242AF4",
"versionEndExcluding": "1.25.3",
"versionStartIncluding": "1.25.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]