CVE-2025-61726
Memory exhaustion in query parameter parsing in net/url
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Issues addressed include a memory exhaustion vulnerability.
*Credits:
jub0bs
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-09-30 CVE Reserved
- 2026-01-20 CVE Published
- 2026-01-29 CVE Updated
- 2026-03-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
| URL | Tag | Source |
|---|---|---|
| https://go.dev/cl/736712 | ||
| https://go.dev/issue/77101 | ||
| https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc | ||
| https://pkg.go.dev/vuln/GO-2026-4341 |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Go Standard Library Search vendor "Go Standard Library" | Net/url Search vendor "Go Standard Library" for product "Net/url" | < 1.24.12 Search vendor "Go Standard Library" for product "Net/url" and version " < 1.24.12" | en |
Affected
| ||||||
| Go Standard Library Search vendor "Go Standard Library" | Net/url Search vendor "Go Standard Library" for product "Net/url" | >= 1.25.0 < 1.25.6 Search vendor "Go Standard Library" for product "Net/url" and version " >= 1.25.0 < 1.25.6" | en |
Affected
| ||||||
