CVE-2025-61723Allocation of Resources Without Limits or Throttling in Standard Library Encoding PEM

Severity
7.5HIGHNVD
EPSS
0.0%
top 88.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateOct 31

Description

The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDgolang/go1.25.01.25.2+1
CVEListV5go_standard_library/encoding_pem1.25.01.25.2+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hjx7-fpxx-mj48: The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input2025-10-30
OSV
CVE-2025-61723: The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input2025-10-29
CVEList
Quadratic complexity when parsing some invalid inputs in encoding/pem2025-10-29
OSV
Quadratic complexity when parsing some invalid inputs in encoding/pem2025-10-29

📋Vendor Advisories

3
Red Hat
encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem2025-10-29
Microsoft
Quadratic complexity when parsing some invalid inputs in encoding/pem2025-10-14
Debian
CVE-2025-61723: golang-1.15 - The processing time for parsing some invalid inputs scales non-linearly with res...2025

💬Community

3
Bugzilla
CVE-2025-61723 docker-distribution: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42]2025-10-31
Bugzilla
CVE-2025-61723 docker-distribution: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43]2025-10-31
Bugzilla
CVE-2025-61723 trivy: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43]2025-10-31
CVE-2025-61723 — HIGH severity | cvebase