Логотип exploitDog
bind:"CVE-2025-68156"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-68156"

Количество 8

Количество 8

nvd логотип

CVE-2025-68156

около 2 месяцев назад

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data stru

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-68156

около 2 месяцев назад

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-68156

около 2 месяцев назад

Expr is an expression language and expression evaluation for Go. Prior ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2025:23729

около 1 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2025:23664

около 2 месяцев назад

Important: opentelemetry-collector security update

EPSS: Низкий
github логотип

GHSA-cfpf-hrx2-8rv6

около 2 месяцев назад

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20099-1

12 дней назад

Security update for coredns

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0327-1

8 дней назад

Security update for alloy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data stru

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2025-68156

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2025:23729

Important: opentelemetry-collector security update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2025:23664

Important: opentelemetry-collector security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-cfpf-hrx2-8rv6

Expr has Denial of Service via Unbounded Recursion in Builtin Functions

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20099-1

Security update for coredns

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:0327-1

Security update for alloy

8 дней назад

Уязвимостей на страницу