Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:3668

Опубликовано: 05 мар. 2026
Источник: rocky
Оценка: Important

Описание

Important: go-rpm-macros security update

This package provides build-stage rpm automation to simplify the creation of Go language (golang) packages. It does not need to be included in the default build root: go-srpm-macros will pull it in for Go packages only.

Security Fix(es):

  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
go-filesystemx86_6413.el9_7go-filesystem-3.6.0-13.el9_7.x86_64.rpm
go-rpm-macrosx86_6413.el9_7go-rpm-macros-3.6.0-13.el9_7.x86_64.rpm
go-rpm-templatesnoarch13.el9_7go-rpm-templates-3.6.0-13.el9_7.noarch.rpm
go-srpm-macrosnoarch13.el9_7go-srpm-macros-3.6.0-13.el9_7.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
redhat
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
nvd
около 2 месяцев назад

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

CVSS3: 7.5
debian
около 2 месяцев назад

The net/url package does not set a limit on the number of query parame ...

rocky
21 день назад

Important: go-rpm-macros security update