CVE-2025-61726

CVE Details

Release Date:2026-01-28
Impact:Important What is this?

Description


The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

See more information about CVE-2025-61726 from MITRE CVE dictionary and NIST NVD


NOTE: The following CVSS metrics and score provided are preliminary and subject to review.


CVSS v3 metrics

Base Score: 7.5
Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Version: 3.1
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: None
Scope: Unchanged
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: High

Errata information


PlatformErrataRelease Date
Oracle Linux version 10 (buildah) ELSA-2026-32972026-02-25
Oracle Linux version 10 (delve) ELSA-2026-38642026-03-05
Oracle Linux version 10 (go-rpm-macros) ELSA-2026-36692026-03-03
Oracle Linux version 10 (golang) ELSA-2026-27062026-02-16
Oracle Linux version 10 (golang-github-openprinting-ipp-usb) ELSA-2026-30922026-02-23
Oracle Linux version 10 (grafana) ELSA-2026-29142026-02-18
Oracle Linux version 10 (grafana-pcp) ELSA-2026-30352026-02-23
Oracle Linux version 10 (image-builder) ELSA-2026-38402026-03-06
Oracle Linux version 10 (osbuild-composer) ELSA-2026-37522026-03-05
Oracle Linux version 10 (podman) ELSA-2026-33362026-02-25
Oracle Linux version 10 (skopeo) ELSA-2026-33432026-02-25
Oracle Linux version 8 (delve) ELSA-2026-27082026-02-16
Oracle Linux version 8 (git-lfs) ELSA-2026-39852026-03-09
Oracle Linux version 8 (golang) ELSA-2026-27082026-02-16
Oracle Linux version 8 (grafana) ELSA-2026-31882026-02-24
Oracle Linux version 8 (grafana-pcp) ELSA-2026-31872026-02-24
Oracle Linux version 8 (osbuild-composer) ELSA-2026-38982026-03-06
Oracle Linux version 9 (buildah) ELSA-2026-32982026-02-25
Oracle Linux version 9 (containernetworking-plugins) ELSA-2026-33412026-02-25
Oracle Linux version 9 (git-lfs) ELSA-2026-39282026-03-05
Oracle Linux version 9 (go-rpm-macros) ELSA-2026-36682026-03-03
Oracle Linux version 9 (golang) ELSA-2026-27092026-02-16
Oracle Linux version 9 (grafana) ELSA-2026-29202026-02-18
Oracle Linux version 9 (grafana-pcp) ELSA-2026-30402026-02-23
Oracle Linux version 9 (image-builder) ELSA-2026-38392026-03-06
Oracle Linux version 9 (osbuild-composer) ELSA-2026-37532026-03-05
Oracle Linux version 9 (podman) ELSA-2026-33372026-02-25
Oracle Linux version 9 (runc) ELSA-2026-32912026-02-25
Oracle Linux version 9 (skopeo) ELSA-2026-33402026-02-25


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete