Vulnerability Report: GO-2025-4006
standard library- CVE-2025-61725, CVE-2025-61725
- Affects: net/mail
- Published: Oct 29, 2025
- Modified: Dec 09, 2025
The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
Affected Packages
-
PathGo VersionsSymbols
-
before go1.24.8, from go1.25.0 before go1.25.2
Aliases
References
- https://go.dev/cl/709860
- https://go.dev/issue/75680
- https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI
- https://vuln.go.dev/ID/GO-2025-4006.json
Credits
- Philippe Antoine (Catena cyber)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.