CVE-2025-58188
High
· CVSS 7.5
Low ImpactExploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.
Component
Go standard library (crypto/x509)
Disclosed
Oct 8, 2025
CVSS Score
7.5
crypto/x509 package panics when validating a certificate chain that contains
a DSA public key, due to a missing interface implementation check. An attacker who
can supply or influence a certificate chain presented during TLS handshake can crash
any program that validates arbitrary certificate chains. Fixed in Go 1.24.8 and
Go 1.25.2.Community Edition
2.11.1
addresses this CVE
Affected CE versions
>= 2.0, < 2.11.1
Enterprise Edition
2.11.2
addresses this CVE
Affected EE versions
>= 2.0, < 2.11.2
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates