CVE-2025-61726Patch(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 6 mentions on most recent observed day (2026-03-11)
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline10 mentions / 5d
02356Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-01: 1Mentions · 2026-02-23: 1Mentions · 2026-03-11: 6Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 5Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-01: 101-2801-2902-0102-2303-11
Signal classification3 categories
Patch
770.0%
General
220.0%
Disclosure
110.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-291
Disclosure1
2026-02-011
Patch1
2026-02-231
Patch1
2026-03-116
General1Patch5
Full discourse10 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    An advisory lists multiple CVEs and notes that security fixes have been applied for versions 18/19, with no details on exploitation or vulnerability specifics.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    The message lists several CVE identifiers and notes that security fixes for Apigee‑Redis versions 17 and 19 are available, implying a vendor patch release.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    The text lists several CVEs and notes that security fixes for apigee‑prometheus‑adapter version 16/19 address them, indicating a patch release.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The notice announces security patches for apigee-hybrid-cassandra-client that address a list of CVEs, without providing exploit details or technical specifics.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The text announces security updates for Apigee products, listing several CVEs that the patch addresses, without providing PoC or exploit details.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    General

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The text enumerates a set of CVEs linked to the apigee-stackdriver-logging-agent without providing further technical, exploit, or patch details.

    00000116
    1.8K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-61726 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/396 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE-2025-61726, indicating the vulnerability has been patched.

    0000035
    30 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Go language (golang) users: A memory exhaustion vulnerability (CVE-2025-61726) in net/url query parsing may lead to service disruption. Consider updating to address this #golang #vulnerability #infosec. https://www.pulsepatch.io/posts/cve-2025-61726-golang-memory-exhaustion-net-url

    Post summary

    The post warns Go users of a memory exhaustion flaw (CVE‑2025‑61726) in net/url query parsing and recommends updating to mitigate the issue; no PoC or active exploitation is reported.

    0000069
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-61726 Memory Exhaustion Vulnerability in Go net/url Package Query Parameter Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-61726

    Post summary

    The text announces CVE-2025-61726 as a memory exhaustion flaw in Go's net/url package's query parameter parsing, without reference to PoC, exploit code, active exploitation, or patch information.

    0000096
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-61726 The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the … https://www.cve.org/CVERecord?id=CVE-2025-61726

    Post summary

    The snippet briefly explains CVE-2025-61726 as a lack of query‑parameter limit in Go's net/url package, without providing PoC, exploitation, or patch details.

    00000176
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more