CVE-2026-58185
published 2026-07-29CVE-2026-58185: The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.34%
27.3th percentile
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 10.0.0 < 10.1.4 | 10.1.4 |
| apache | traffic_server | 8.0.0 – 8.1.9 | — |
| apache | traffic_server | >= 9.0.0 < 9.2.15 | 9.2.15 |
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.1.3 | — |
| apache_software_foundation | apache_traffic_server | 8.0.0 – 8.1.9 | — |
| apache_software_foundation | apache_traffic_server | 9.0.0 – 9.2.14 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58185 Apache Traffic Server: use-after-free in the intercept plugin
bugzilla·2026-07-29·CVSS 5.9
CVE-2026-58185 [MEDIUM] CVE-2026-58185 Apache Traffic Server: use-after-free in the intercept plugin
CVE-2026-58185 Apache Traffic Server: use-after-free in the intercept plugin
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Bugzilla
CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [epel-all]
bugzilla·2026-07-29·CVSS 5.9
CVE-2026-58185 [MEDIUM] CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [epel-all]
CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Discussion:
FEDORA-EPEL-2026-943e511d48 (trafficserver-9.2.15-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-943e511d48
Bugzilla
CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [fedora-all]
bugzilla·2026-07-29·CVSS 5.9
CVE-2026-58185 [MEDIUM] CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [fedora-all]
CVE-2026-58185 trafficserver: use-after-free in the intercept plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Bugzilla
CVE-2025-58185 forgejo: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 forgejo: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 forgejo: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-58185 nebula: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 nebula: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 nebula: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-58185 golang-github-hashicorp-hc-install: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-hashicorp-hc-install: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-hashicorp-hc-install: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
Bugzilla
CVE-2025-58185 golang-etcd-bbolt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-etcd-bbolt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-etcd-bbolt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's p
Bugzilla
CVE-2025-58185 yggdrasil: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 yggdrasil: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 yggdrasil: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-58185 geoipupdate: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 geoipupdate: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 geoipupdate: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy
Bugzilla
CVE-2025-58185 golang-github-eclipse-paho-mqtt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-eclipse-paho-mqtt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-eclipse-paho-mqtt: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It
Bugzilla
CVE-2025-58185 golang-github-nats-io-streaming-server: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-nats-io-streaming-server: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-nats-io-streaming-server: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05
Bugzilla
CVE-2025-58185 yq: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 yq: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
CVE-2025-58185 yq: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-32169dd0b8 (yq-4.53.3-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-32169dd0b8
---
FEDORA-EPEL-2026-
Bugzilla
CVE-2025-58185 go-fdo-client: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 go-fdo-client: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 go-fdo-client: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-58185 ceph: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 ceph: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 ceph: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clos
Bugzilla
CVE-2025-58185 cheat: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 cheat: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 cheat: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clo
Bugzilla
CVE-2025-58185 anubis: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 anubis: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 anubis: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-58185 netdata: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 netdata: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 netdata: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-58185 hut: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 hut: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
CVE-2025-58185 hut: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-ed208f5337 (hut-0.8.0-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-ed208f5337
---
FEDORA-2026-32113d4817 (hut-0.8.0
Bugzilla
CVE-2025-58185 golang-github-hashicorp-msgpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-hashicorp-msgpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-hashicorp-msgpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It
Bugzilla
CVE-2025-58185 golang-github-distribution-3: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-distribution-3: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-distribution-3: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-58185 golang-github-geertjohan-rice: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-geertjohan-rice: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-geertjohan-rice: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It i
Bugzilla
CVE-2025-58185 golang-k8s-apiextensions-apiserver: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-k8s-apiextensions-apiserver: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-k8s-apiextensions-apiserver: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
Bugzilla
CVE-2025-58185 mlpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 mlpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 mlpack: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-58185 golang-github-bobesa-domain-util: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-bobesa-domain-util: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-bobesa-domain-util: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
I
Bugzilla
CVE-2025-58185 golang-x-debug: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-x-debug: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-x-debug: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's poli
Bugzilla
CVE-2025-58185 golang-github-pelletier-toml: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-pelletier-toml: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-pelletier-toml: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-58185 osbuild-composer: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 osbuild-composer: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 osbuild-composer: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's po
Bugzilla
CVE-2025-58185 cri-tools1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 cri-tools1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 cri-tools1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-58185 golang-k8s-pod-security-admission: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-k8s-pod-security-admission: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-k8s-pod-security-admission: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
Bugzilla
CVE-2025-58185 golang-mvdan-xurls: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-mvdan-xurls: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-mvdan-xurls: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's
Bugzilla
CVE-2025-58185 golang-github-nats-io-jwt-2: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-nats-io-jwt-2: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-nats-io-jwt-2: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-795b0d0367 (vhs-0.9.0-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-795b0d0367
Bugzilla
CVE-2025-58185 golang-github-spyzhov-ajson: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-spyzhov-ajson: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-spyzhov-ajson: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-58185 golang-github-facebookincubator-dhcplb: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-facebookincubator-dhcplb: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-facebookincubator-dhcplb: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05
Bugzilla
CVE-2025-58185 golang-github-pact-foundation: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-pact-foundation: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-pact-foundation: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It i
Bugzilla
CVE-2025-58185 golang-github-haproxytech-dataplaneapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-haproxytech-dataplaneapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-haproxytech-dataplaneapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05
Bugzilla
CVE-2025-58185 golang-github-googleapis-gnostic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-googleapis-gnostic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-googleapis-gnostic: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
I
Bugzilla
CVE-2025-58185 golang-github-cloudflare-redoctober: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-cloudflare-redoctober: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-cloudflare-redoctober: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13
Bugzilla
CVE-2025-58185 kubernetes1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 kubernetes1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 kubernetes1.29: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's poli
Bugzilla
CVE-2025-58185 gitjacker: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 gitjacker: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 gitjacker: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-58185 golang-github-aws-lambda: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-aws-lambda: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-aws-lambda: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fed
Bugzilla
CVE-2025-58185 golang-github-hexdigest-gowrap: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-hexdigest-gowrap: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-hexdigest-gowrap: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It
Bugzilla
CVE-2025-58185 golang-github-cloudflare: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-cloudflare: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-cloudflare: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fed
Bugzilla
CVE-2025-58185 nng: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 nng: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 nng: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
CVE-2025-58185 vhs: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-7646f2a691 (vhs-0.10.0-4.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7646f2a691
Bugzilla
CVE-2025-58185 golang-k8s-kube-openapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-k8s-kube-openapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-k8s-kube-openapi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedo
Bugzilla
CVE-2025-58185 golang-github-google-martian: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 golang-github-google-martian: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 golang-github-google-martian: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-58185 thrift: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 thrift: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 thrift: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-58185 grpc: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 grpc: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 grpc: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clos
Bugzilla
CVE-2025-58185 git-credential-azure: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
bugzilla·2025-10-31·CVSS 5.3
CVE-2025-58185 [MEDIUM] CVE-2025-58185 git-credential-azure: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
CVE-2025-58185 git-credential-azure: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora'
2026-07-29
Published