Go standard library encoding/asn1

2 known vulnerabilities in Go standard library encoding/asn1, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-33818 CVSS 7.5 high Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
  • CVE-2025-58185 CVSS 5.3 medium Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.