VDB
GCVE-VVD-MAGEIA-2026-35
GCVE-VVD-MAGEIA-2026-35
Advisory Published
net/http: memory exhaustion in Request.ParseForm. (CVE-2025-61726)
archive/zip: denial of service when parsing arbitrary ZIP archives.
(CVE-2025-61728)
crypto/tls: handshake messages may be processed at the incorrect
encryption level. (CVE-2025-61730)
cmd/go: bypass of flag sanitization can lead to arbitrary code
execution. (CVE-2025-61731)
Potential code smuggling via doc comments in cmd/cgo. (CVE-2025-61732)
cmd/go: unexpected code execution when invoking toolchain.
(CVE-2025-68119)
crypto/tls: Config.Clone copies automatically generated session ticket
keys, session resumption does not account for the expiration of full
certificate chain. (CVE-2025-68121)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | golang | 0 (affected), 1.24.13-1.mga9 (unaffected) | — |
| AWS | config | — | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.