Executive brief
A vulnerability in the Go programming language's standard library could allow an attacker to crash a web server or application. By sending a specially crafted web request with an extremely large number of unique parameters, an attacker can force the application to consume all available system memory. This results in a denial-of-service (DoS) condition, making the service unavailable to legitimate users.
Technical details
A memory exhaustion vulnerability exists in the Go 'net/url' package and 'net/http.Request.ParseForm' method. While URL query parameters are typically constrained by request header size limits, 'ParseForm' can process large URL-encoded bodies containing a vast number of unique keys. Because the package does not enforce a maximum limit on the number of parameters, an attacker can send a crafted request that forces the application to allocate excessive memory during parsing. This can lead to a process crash or system-wide denial of service. The issue is fixed in Go versions 1.24.12 and 1.25.6.
Affected products
- Google Go before 1.24.12, 1.25.0 before 1.25.6
Timeline
- 2026-01-07: disclosed: Issue opened in Go repository
- 2026-01-28: advisory: CVE published and Go vulnerability report released