Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade golang-1.24 | Jul 23, 2026 | Jul 23, 2026 |
| Suse | — | Upgrade go1.24-libstdUpgrade go1.24-opensslUpgrade go1.24Upgrade go1.24-docUpgrade go1.24-raceUpgrade go1.24-openssl-raceUpgrade govulncheck-vulndb | Jan 30, 2025 | Jan 28, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub