Логотип exploitDog
bind: "CVE-2025-68156"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-68156"

Количество 11

Количество 11

redhat логотип

CVE-2025-68156

3 месяца назад

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data s...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-68156

3 месяца назад

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data stru

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-68156

3 месяца назад

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-68156

3 месяца назад

Expr is an expression language and expression evaluation for Go. Prior ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260327-73-0013

4 дня назад

Уязвимость opentelemetry-collector-contrib

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2025:23729

3 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2025:23664

3 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
github логотип

GHSA-cfpf-hrx2-8rv6

3 месяца назад

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20140-1

около 2 месяцев назад

Security update for alloy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20099-1

2 месяца назад

Security update for coredns

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0327-1

2 месяца назад

Security update for alloy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data s...

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data stru

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-68156

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260327-73-0013

Уязвимость opentelemetry-collector-contrib

CVSS3: 7.5
0%
Низкий
4 дня назад
rocky логотип
RLSA-2025:23729

Important: opentelemetry-collector security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:23664

Important: opentelemetry-collector security update

0%
Низкий
3 месяца назад
github логотип
GHSA-cfpf-hrx2-8rv6

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20140-1

Security update for alloy

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20099-1

Security update for coredns

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0327-1

Security update for alloy

2 месяца назад

Уязвимостей на страницу