Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61726

Опубликовано: 28 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

EPSS

Процентиль: 8%
0.0003
Низкий

7.5 High

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 дней назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
debian
10 дней назад

The net/url package does not set a limit on the number of query parame ...

CVSS3: 7.5
github
10 дней назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

suse-cvrf
16 дней назад

Security update for go1.25

suse-cvrf
16 дней назад

Security update for go1.24

EPSS

Процентиль: 8%
0.0003
Низкий

7.5 High

CVSS3

Дефекты