CYBER CODE RED

Get real-time updates on Telegram

P4Verified

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

CVE-2025-61729, CVE-2025-64460, CVE-2025-66471, CVE-2025-69223, CVE-2026-25679, CVE-2026-27137, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-33186, CVE-2026-33810, CVE-2026-33811, CVE-2026-33815, CVE-2026-33816, CVE-2026-35469, CVE-2026-39821, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39832, CVE-2026-39835, CVE-2026-40192, CVE-2026-42151, CVE-2026-42154, CVE-2026-42508, CVE-2026-46595 affects azl3 golang 1.25.5-1 on Azure Linux 3.0. CVSS base score 7.5 (Microsoft Security Response Center). EPSS 0.00457 (percentile 0.37427), scored 2026-10-03. Fixed version: 0:1.1.3-1.el10em.

CVE
CVE-2025-61729, CVE-2025-64460, CVE-2025-66471, CVE-2025-69223, CVE-2026-25679, CVE-2026-27137, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-33186, CVE-2026-33810, CVE-2026-33811, CVE-2026-33815, CVE-2026-33816, CVE-2026-35469, CVE-2026-39821, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39832, CVE-2026-39835, CVE-2026-40192, CVE-2026-42151, CVE-2026-42154, CVE-2026-42508, CVE-2026-46595
Product
azl3 golang 1.25.5-1 on Azure Linux 3.0
CCR priority
30.1 /100 (P4)
CVSS
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Microsoft Security Response Center
EPSS
0.00457 · percentile 0.37427 · 2026-10-03
KEV
no

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-61729.html