CVE-2025-58187Patch(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 7 mentions (2026-03-11); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-03-11: 7Mentions · 2026-07-20: 1Patch / Workaround · 2026-03-11: 7Patch / Workaround · 2026-07-20: 1Technical Details · 2026-07-20: 103-1107-20
Signal classification1 categories
Patch
8100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-117
Patch7
2026-07-201
Patch1
Full discourse8 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The notice lists multiple CVE identifiers and states that security fixes are being applied, but it provides no further technical detail or exploit information.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    The post lists several CVEs and notes that security fixes have been released for apigee-redis versions 17 and 19.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    The excerpt lists multiple CVE IDs and confirms that security fixes for apigee‑prometheus‑adapter 16/19 are available.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68156 CVE-2025-61729 CVE-2025-4674 CVE-2025-29786 N/A Security fixes for apigee-open-telemetry-collector: 14/19

    Post summary

    The text lists multiple CVE identifiers and indicates that security fixes (patches) are available for apigee-open-telemetry-collector.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    CVE-2025-47907 CVE-2025-4674 N/A Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: CVE-2025-61729 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 N/A Security fixes for apigee-open-telemetry-collector 13/19

    Post summary

    The message lists CVE identifiers and announces security fixes for specific Apigee components, but offers no technical details, PoC, or exploitation information.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The text announces security fixes for apigee-hybrid-cassandra-client that address several CVEs, without providing further technical details or exploitation context.

    1000081
    1.8K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Astra Control Center alert: CVE-2025-58187 (CVSS 7.5) Attackers could disrupt service or cause a denial of service. No workaround; upgrade to a vendor-listed fixed release. https://vulnipulse.com/advisories/netapp-ntap-20260612-0003 #NetApp #AstraControlCenter #CyberSecurity #CVE

    Post summary

    The advisory informs users of CVE-2025-58187 (CVSS 7.5) and recommends upgrading to a vendor‑fixed release, without mentioning PoC, exploit code, or active exploitation.

    0000036
    6 followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The text states that apigee-stackdriver-logging-agent addresses a number of listed CVEs without providing evidence of exploitation, PoC, or detailed vulnerability data.

    00000116
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more