- Description
- Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
- Source
- security@golang.org
- NVD status
- Analyzed
- Products
- go
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-295
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos VMware ❗ CVE-2025-61725 ❗ CVE-2025-58188 ❗ CVE-2025-58187 ➡️ Más info: https://t.co/f2QzldWdbF https://t.co/vkGw6I6sgQ
@CERTpy
15 Jan 2026
98 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
[URGENT] Fedora 38 #Security Update: complyctl patched for high-severity flaw CVE-2025-58188. Container compliance bypass risk. 🔐 Read more: 👉 https://t.co/cx3fFNccY8 #Security https://t.co/4fFezrnG2J
@Cezar_H_Linux
14 Jan 2026
28 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
Fedora releases critical Gobuster update fixing CVE-2025-58188, a DoS vulnerability, by unretiring the package and upgrading to version 3.8.2. Users should update promptly. #infosec https://t.co/51qMtLi1Zr
@threatcluster
22 Dec 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 CRITICAL UPDATE: #Fedora patches #GoBuster to address CVE-2025-58188 (v3.8.2). This directory/DNS busting tool is vital for pentesters. A flaw in it could compromise security audits. Read more: 👉 https://t.co/HNf24Us2e2 #Security https://t.co/obwsGfitiE
@Cezar_H_Linux
22 Dec 2025
36 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
URGENT: #Fedora docker-buildkit security patches available for CVE-2025-58183, CVE-2025-58185, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723 Read more: 👉 https://t.co/1s46wqrgPS #Security https://t.co/WcSSlZybiB
@Cezar_H_Linux
27 Nov 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-58188 Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This af… https://t.co/FeAzRgdOBE
@CVEnew
29 Oct 2025
236 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E1AB9501-4F7D-4E37-BA0A-4E57B082530C",
"versionEndExcluding": "1.24.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C196D175-EF20-476C-8C64-1B9F5C50AA2D",
"versionEndExcluding": "1.25.2",
"versionStartIncluding": "1.25.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]