Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5w8-q4qc-rx2x | golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption |
Ubuntu USN |
USN-7956-1 | Google Guest Agent vulnerability |
Sat, 20 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 11 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:* |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang crypto Golang ssh |
|
| Vendors & Products |
Golang
Golang crypto Golang ssh |
Thu, 20 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CVE-2025-58181 in golang.org/x/crypto/ssh | Unbounded memory consumption in golang.org/x/crypto/ssh |
Wed, 19 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption. | |
| Title | CVE-2025-58181 in golang.org/x/crypto/ssh | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-11-20T17:14:59.856Z
Reserved: 2025-08-27T14:50:58.691Z
Link: CVE-2025-58181
Updated: 2025-11-19T20:48:46.369Z
Status : Analyzed
Published: 2025-11-19T21:15:50.850
Modified: 2025-12-11T19:29:24.900
Link: CVE-2025-58181
OpenCVE Enrichment
Updated: 2025-11-21T09:16:06Z
Github GHSA
Ubuntu USN