VDB
DEBIAN-CVE-2025-58181
DEBIAN-CVE-2025-58181
PUBLISHED
CVSS 5.300000190734863 MEDIUM
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | golang-go.crypto | 0.0, 1:0.22.0-1, 1:0.24.0-1 |
| Debian:14 | golang-go.crypto | 0.43.0-2, 0.43.0-1, 0.42.0-4 |
| Debian:13 | golang-go.crypto | *, 0, 1:0.25.0-1 |
| Debian:12 | golang-go.crypto | *, *, * |
Exploit Intelligence
- CHANGELOG-v1.73.14.yml (github-poc)
- 2026.xml (github-poc)
- 2026.xml (github-poc)
Timeline
- Nov 19, 2025 CVE Published
- Apr 28, 2026 CVE Updated