CVE-2025-58188
Severity
7.5HIGH
EPSS
0.0%
top 99.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 29
Latest updateNov 4
Description
Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-7wwx-xj66-r44x: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal↗2025-10-30
OSV▶
CVE-2025-58188: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal↗2025-10-29
📋Vendor Advisories
3💬Community
4Bugzilla▶
CVE-2025-58188 docker-distribution: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42]↗2025-11-04
Bugzilla▶
CVE-2025-58188 trivy: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]↗2025-11-01
Bugzilla▶
CVE-2025-58188 docker-distribution: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]↗2025-11-01
Bugzilla▶
CVE-2025-58188 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509↗2025-10-29