CVE 5.3 MEDIUM

CVE-2025-58181 in golang.org/x/crypto/ssh_CVE-2025-58181

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Description

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Basic Information

ID CVE-2025-58181
Source Go
Published Nov 19, 2025 at 20:33
Modified Nov 19, 2025 at 20:49

Affected Product

Vendor golang.org/x/crypto
Product golang.org/x/crypto/ssh

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.