CVE-2025-58181: Golang Crypto

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Affected products

  • Golang Crypto: before 0.45.0 (fixed in 0.45.0)

Published 2025-11-19. Last modified 2026-06-17.