CVE-2025-61726

Published: January 16, 2026Last modified: January 17, 2026

Description

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.24.12-r0)
25 LTSgoFixed (1.24.12-r0)
StreamgoFixed (1.25.6-r0)
Hardened Containers23 LTSgoFixed (1.24.12-r0)
25 LTSgoFixed (1.24.12-r0)
StreamgoFixed (1.25.6-r0)

References

ON THIS PAGE