VulnerabilityAnalyzed
CVE-2025-58181
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
MEDIUM 5.3EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- golang/crypto
- Source
- security@golang.org
References
- https://go.dev/cl/721961Patch
- https://go.dev/issue/76363Issue Tracking
- https://groups.google.com/g/golang-announce/c/w-oX3UxNcZAMailing List
- https://pkg.go.dev/vuln/GO-2025-4134Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.