VDB
GO-2025-3488
GO-2025-3488
PUBLISHED
Unexpected memory consumption during token parsing in golang.org/x/oauth2
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | sql_exporter | 0, 0, 0 |
| wolfi | kor | 0, 0, 0 |
| chainguard | prometheus-pushgateway-1.4 | 0, 0 |
| wolfi | istio-1.25 | 0, 0, 0 |
| chainguard | kube-logging-logging-operator-4.1 | 0, 0, 0 |
| chainguard | kyverno-policy-reporter-kyverno-plugin-fips | 0, 0, 0 |
| chainguard | velero-fips | 0, 0 |
| chainguard | flyte | 0, 0 |
| wolfi | distribution | 0, 0, 0 |
| wolfi | cluster-api-aws-controller | 0, 0, 0 |
| chainguard | kiam | 0, 0, 0 |
| wolfi | volume-modifier-for-k8s | 0, 0, 0 |
| chainguard | grafana-11.4 | 0, 0 |
| chainguard | step-kms-plugin-fips | 0, 0 |
| wolfi | sriov-network-device-plugin | 0, 0, 0 |
| chainguard | thanos-operator | 0, 0 |
| wolfi | cortex | 0, 0, 0 |
| chainguard | gcp-compute-persistent-disk-csi-driver-1.15 | 0, 0 |
| chainguard | kubernetes-csi-external-resizer-fips | 0, 0, 0 |
| chainguard | consul-k8s-fips-1.6 | 0, 0 |
…and 1052 more
Timeline
- Feb 26, 2025 CVE Published
- Mar 24, 2026 CVE Updated
References
- https://go.dev/issue/71490 report
- https://go.dev/cl/652155 patch