Get real-time updates on Telegram
P5Verified
CVE-2025-22870: golang-1.23 (exact versions not specified); +2 more affected products
CVE-2025-22870 affects golang-1.23. EPSS 0.00409 (percentile 0.32894), scored 2026-10-05. Fixed version: 1.23.7. Fixed version: 1.24.1-1. Fixed version: 0.36.0.
Affected technology
golang-1.23 · Exact affected versions not specified by the source
Vendor not specified by the source
golang-1.24 · Exact affected versions not specified by the source
Vendor not specified by the source
golang.org/x/net · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- Product
- golang-1.23
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00409 · percentile 0.32993 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- OSV.dev · Source record · observed 2026-10-07 03:19:31.921362+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-22870.html