CVE-2025-47907Patch(golang / go)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-11); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-11: 3Mentions · 2026-06-20: 1Patch / Workaround · 2026-03-11: 3Technical Details · 2026-06-20: 103-1106-20
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-113
Patch3
2026-06-201
Disclosure1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    ⚠️ Atenção, administradores openSUSE! A CVE-2025-47907 no azure-storage-azcopy pode corromper silenciosamente seus dados durante transfers para o Azure. Saiba mais- > http://tinyurl.com/2kuhdwcd #openSUSE https://t.co/u4Bgjlep7v

    Post summary

    The tweet alerts openSUSE administrators to CVE‑2025‑47907 in azure‑storage‑azcopy that may silently corrupt data transfers to Azure; no PoC, exploit, patch, or active exploitation claims are included.

    1000074
    1.5K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The note lists multiple CVEs covered by security fixes for releases 18/19, indicating that patches exist but no further technical or exploitation detail is provided.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    CVE-2025-47907 CVE-2025-4674 N/A Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: CVE-2025-61729 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 N/A Security fixes for apigee-open-telemetry-collector 13/19

    Post summary

    The text announces security fixes for apigee-kube-rbac-proxy and apigee-open-telemetry-collector that address several CVEs, without providing PoC, exploit, or technical vulnerability details.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The message lists multiple CVE identifiers that are covered by an update to the apigee-stackdriver-logging-agent, indicating a patch or mitigation is provided.

    00000116
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more