CVE-2025-30204Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-405

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 103-18
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #openSUSE Leap 16.0 docker-stable patch drops (2026-20366-1). Fixes CVE-2025-30204 (JWT parsing memory bomb, CVSS 8.7) and CVE-2025-58181. Read more: 👉 https://tinyurl.com/mvezxn3r #Security https://t.co/DjhtmpXDLJ

    Post summary

    The tweet announces a critical openSUSE Leap 16.0 Docker patch addressing CVE‑2025‑30204 (a JWT parsing memory bomb, CVSS 8.7) and CVE‑2025‑58181, with a link for further details.

    00000125
    1.5K followersView on X

Explore more