CVE-2025-58181 — Allocation of Resources Without Limits or Throttling in X Crypto Golang.org X Crypto SSH
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 74.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateJan 13
Description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
5OSV▶
CVE-2025-58181: SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause un↗2025-11-19
📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2025-58181 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication↗2025-11-19