CVE-2025-58186

Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GoCNA
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
trixie
no-dsa
bookworm
no-dsa
golang-1.19
bookworm
vulnerable
trixie
no-dsa
golang-1.24
trixie
no-dsa
bookworm
no-dsa
forky
1.24.9-1
fixed
sid
1.24.9-1
fixed
golang-1.25
forky
1.25.3-1
fixed
sid
1.25.3-1
fixed
trixie
no-dsa
bookworm
no-dsa