CVE-2025-66506
ADVISORY - githubSummary
Function identity.extractIssuerURL currently splits (via a call to strings.Split) its argument (which is untrusted data) on periods.
As a result, in the face of a malicious request with an (invalid) OIDC identity token in the payload containing many period characters, a call to extractIssuerURL incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. Relevant weakness: CWE-405: Asymmetric Resource Consumption (Amplification)
Details See identity.extractIssuerURL
Impact Excessive memory allocation
Common Weakness Enumeration (CWE)
Asymmetric Resource Consumption (Amplification)
Asymmetric Resource Consumption (Amplification)
Asymmetric Resource Consumption (Amplification)
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumGoLang
-
Amazon
-
CVSS SCORE
N/AmediumRed Hat
3.9
CVSS SCORE
7.5highChainguard
CGA-63x2-wrq7-39v8
-
Chainguard
CGA-68w4-g9f6-x6vr
-
Chainguard
CGA-949m-8gfh-7g55
-
Chainguard
CGA-995x-7m99-76hh
-
Chainguard
CGA-fcph-w3jq-r4pq
-
Chainguard
CGA-g74c-2hwg-8qc2
-
Chainguard
CGA-grw7-gm24-g7m3
-
Chainguard
CGA-h35h-86pv-c4c2
-
Chainguard
CGA-h35r-2hv6-9x22
-
Chainguard
CGA-h73h-2rrx-q93g
-
Chainguard
CGA-j425-fgw8-gvmc
-
Chainguard
CGA-j98c-55pc-5jq6
-
Chainguard
CGA-mpjp-6jv4-h7v2
-
Chainguard
CGA-pxff-gffw-462f
-
Chainguard
CGA-qm2c-c9vf-hcr2
-
Chainguard
CGA-qp55-j8p9-hr42
-
Chainguard
CGA-rp36-3p5h-qrc2
-
Chainguard
CGA-xvcq-j77g-cq82
-
minimos
MINI-5xp8-9wjx-xh4r
-
minimos
MINI-6m5x-8p33-644h
-
minimos
MINI-6q37-vch2-7532
-
minimos
MINI-95vh-j973-2gw5
-
minimos
MINI-cfw4-843h-w9v3
-
minimos
MINI-cq6f-r5hh-798r
-
minimos
MINI-ghrm-pmxm-88v6
-
minimos
MINI-mhrj-68j6-8jwc
-
minimos
MINI-mvf2-r6ph-674f
-
minimos
MINI-pmw6-jv27-qjmq
-
minimos
MINI-vr2m-fcmr-jh6r
-
minimos
MINI-wv6c-h2gj-87p2
-
minimos
MINI-x644-hq54-q5r4
-
minimos
MINI-x9xv-fc8w-x4q5
-