Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c5f-9mj4-m247

Опубликовано: 05 янв. 2026
Источник: github
Github: Прошло ревью

Описание

flagd: Multiple Go Runtime CVEs Impact Security and Availability

Summary

In 2025, several vulnerabilities in the Go Standard Library were disclosed, impacting Go-based applications like flagd (the evaluation engine for OpenFeature). These CVEs primarily focus on Denial of Service (DoS) through resource exhaustion and Race Conditions in database handling.

CVE IDImpacted PackageSeverityDescription & Impact on flagd
CVE-2025-47907database/sql7.0 (High)Race Condition: Canceling a query during a Scan call can return data from the wrong query. Critical if flagd uses SQL-based sync providers (e.g., Postgres), potentially leading to incorrect flag configurations.
CVE-2025-61725net/mail7.5 (High)DoS: Inefficient complexity in ParseAddress. Attackers can provide crafted email strings with large domain literals to exhaust CPU if flagd parses email-formatted metadata.
CVE-2025-61723encoding/pem7.5 (High)DoS: Quadratic complexity when parsing invalid PEM inputs. Relevant if flagd loads TLS certificates or keys via PEM files from untrusted sources.
CVE-2025-61729crypto/x5097.5 (High)Resource Exhaustion: HostnameError.Error() lacks string concatenation limits. A malicious TLS certificate with thousands of hostnames could crash flagd during connection handshakes.
CVE-2025-58188net/httpMediumRequest Smuggling: Improper header handling in HTTP/1.1. Could allow attackers to bypass security filters positioned in front of flagd sync or evaluation APIs.
CVE-2025-58187archive/zipMediumDoS: Improper validation of malformed ZIP archives. Impacts flagd if configured to fetch and unpack zipped configuration bundles from remote providers.

Пакеты

Наименование

github.com/open-feature/flagd/core

go
Затронутые версииВерсия исправления

< 0.13.1

0.13.1

Наименование

github.com/open-feature/flagd/flagd-proxy

go
Затронутые версииВерсия исправления

< 0.8.2

0.8.2

Наименование

github.com/open-feature/flagd/flagd

go
Затронутые версииВерсия исправления

< 0.13.1

0.13.1

Дефекты

CWE-20
CWE-362
CWE-400
CWE-407
CWE-444
CWE-770

Дефекты

CWE-20
CWE-362
CWE-400
CWE-407
CWE-444
CWE-770