ZeroHour

CVE-2025-58181

CVSS 3.1
5.3 medium
EPSS
<1%p45
Published
()
Modified
Description

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Vendors
golang
Products
crypto
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.