Описание
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
golang-golang-x-oauth2 | fixed | 0.27.0-1 | package | |
golang-golang-x-oauth2 | no-dsa | bookworm | package | |
golang-golang-x-oauth2 | ignored | bullseye | package |
Примечания
https://pkg.go.dev/vuln/GO-2025-3488
https://go-review.googlesource.com/c/oauth2/+/652155
https://github.com/golang/go/issues/71490
Связанные уязвимости
CVSS3: 7.5
ubuntu
4 месяца назад
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVSS3: 7.5
redhat
4 месяца назад
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVSS3: 7.5
nvd
4 месяца назад
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.