CVE-2025-61729Patch(golang / go)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 8 mentions (2026-03-11); latest day: 1
  • 9 total mentions across 2 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline9 mentions / 2d
02468Mentions · 2026-03-11: 8Mentions · 2026-03-15: 1Patch / Workaround · 2026-03-11: 8Technical Details · 2026-03-15: 103-1103-15
Signal classification2 categories
Patch
888.9%
Disclosure
111.1%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-118
Patch8
2026-03-151
Disclosure1
Full discourse9 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The text lists CVE identifiers that have been addressed by security fixes, with no mention of PoCs, exploitation tools, or active attacks.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    The statement enumerates several CVEs and confirms that security fixes are available for apigee-redis versions 17 and 19.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    This notice lists several CVE identifiers and announces that security fixes are available for apigee-prometheus-adapter 16/19, but does not provide technical details or exploit information.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68156 CVE-2025-61729 CVE-2025-4674 CVE-2025-29786 N/A Security fixes for apigee-open-telemetry-collector: 14/19

    Post summary

    The text lists several CVE identifiers and notes that security fixes are available for apigee‑open‑telemetry‑collector; no exploit details or PoC is mentioned.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    CVE-2025-47907 CVE-2025-4674 N/A Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: CVE-2025-61729 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 N/A Security fixes for apigee-open-telemetry-collector 13/19

    Post summary

    Vendor has released security fixes for apigee-kube-rbac-proxy and apigee-open-telemetry-collector, addressing several CVEs.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The text announces security fixes for apigee-hybrid-cassandra-client that address several CVEs, with no exploitation or PoC details provided.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The text reports that security fixes (patches) are available for a set of CVEs affecting Apigee components, but provides no detailed technical or exploit information.

    1000097
    1.8K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical security advisory for #Fedora 42 users! 🛠️ The golang-github-openprinting-ipp-usb package (version < 0.9.31) is vulnerable to a DoS attack via CVE-2025-61729. Read more: 👉 https://tinyurl.com/msjp2rwc #Security https://t.co/CR4Jlv5VFV

    Post summary

    This tweet announces a critical DoS vulnerability (CVE-2025-61729) in the golang-github-openprinting-ipp-usb package for Fedora 42, providing technical details but no PoC, exploit code, or patch information.

    00000174
    1.4K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The apigee‑stackdriver‑logging‑agent update addresses a list of CVEs, indicating a patch release without revealing technical details or exploit code.

    00000116
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more