Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. golang.org/x/crypto
  4. ›
  5. CVE-2025-58181

CVE-2025-58181: golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

November 19, 2025

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

References

  • github.com/advisories/GHSA-j5w8-q4qc-rx2x
  • go.dev/cl/721961
  • go.dev/issue/76363
  • groups.google.com/g/golang-announce/c/w-oX3UxNcZA
  • nvd.nist.gov/vuln/detail/CVE-2025-58181
  • pkg.go.dev/vuln/GO-2025-4134

Code Behaviors & Features

Detect and mitigate CVE-2025-58181 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.45.0

Fixed versions

  • 0.45.0

Solution

Upgrade to version 0.45.0 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

go/golang.org/x/crypto/CVE-2025-58181.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 24 Nov 2025 00:19:48 +0000.