HomeDefault status
unaffected
Any version before 1.24.8
affected
1.25.0 (semver) before 1.25.2
affected
Description
Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
Problem types
Product status
Any version before 1.24.8
1.25.0 (semver) before 1.25.2
Credits
Jakub Ciolek
References
www.openwall.com/lists/oss-security/2025/10/08/1
groups.google.com/g/golang-announce/c/4Emdl2iQ_bI
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.