CVE-2025-47914

5.3 MEDIUM
Published: November 19, 2025 Modified: December 11, 2025

Description

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://go.dev/cl/721960
Source: security@golang.org
Patch
https://go.dev/issue/76364
Source: security@golang.org
Issue Tracking Patch
https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA
Source: security@golang.org
Mailing List
https://pkg.go.dev/vuln/GO-2025-4135
Source: security@golang.org
Vendor Advisory

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.3 / 10.0
EPSS (Exploit Probability)
0.0%
3th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

golang