Junglewise Threat Intelligence

CVE-2025-61726: Go net/url memory exhaustion in query parameter parsing

CVE-2025-61726 · Severity: high · CVSS 7.5 · Published 2026-01-28

Technologies: stdlib (Go). Vendors: Google, Go.

Executive brief

A vulnerability in the Go programming language's standard library could allow an attacker to crash a web server or application. By sending a specially crafted web request with an extremely large number of unique parameters, an attacker can force the application to consume all available system memory. This results in a denial-of-service (DoS) condition, making the service unavailable to legitimate users.

Technical details

A memory exhaustion vulnerability exists in the Go 'net/url' package and 'net/http.Request.ParseForm' method. While URL query parameters are typically constrained by request header size limits, 'ParseForm' can process large URL-encoded bodies containing a vast number of unique keys. Because the package does not enforce a maximum limit on the number of parameters, an attacker can send a crafted request that forces the application to allocate excessive memory during parsing. This can lead to a process crash or system-wide denial of service. The issue is fixed in Go versions 1.24.12 and 1.25.6.

Affected products

  • Google Go before 1.24.12, 1.25.0 before 1.25.6

Timeline

  • 2026-01-07: disclosed: Issue opened in Go repository
  • 2026-01-28: advisory: CVE published and Go vulnerability report released

References

Related threats