Severity
7.5HIGH
EPSS
0.0%
top 99.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateNov 4

Description

Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Gostdlib1.25.01.25.2+1
NVDgolang/go1.25.01.25.2+1
CVEListV5go_standard_library/crypto/x5091.25.01.25.2+1
Debiangolang-1.24< 1.24.8-1
Debiangolang-1.25< 1.25.2-1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7wwx-xj66-r44x: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal2025-10-30
CVEList
Panic when validating certificates with DSA public keys in crypto/x5092025-10-29
OSV
CVE-2025-58188: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal2025-10-29
OSV
Panic when validating certificates with DSA public keys in crypto/x5092025-10-29

📋Vendor Advisories

3
Red Hat
crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x5092025-10-29
Microsoft
Panic when validating certificates with DSA public keys in crypto/x5092025-10-14
Debian
CVE-2025-58188: golang-1.15 - Validating certificate chains which contain DSA public keys can cause programs t...2025

💬Community

4
Bugzilla
CVE-2025-58188 docker-distribution: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]2025-11-04
Bugzilla
CVE-2025-58188 trivy: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]2025-11-01
Bugzilla
CVE-2025-58188 docker-distribution: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]2025-11-01
Bugzilla
CVE-2025-58188 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x5092025-10-29