CVE-2025-61723
High
· CVSS 7.5
Low ImpactExploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.
Component
Go standard library (encoding/pem)
Disclosed
Oct 8, 2025
CVSS Score
7.5
encoding/pem package exhibits non-linear processing time when parsing certain
invalid PEM inputs. Programs that parse untrusted PEM data can be driven into excessive
CPU consumption, causing a denial of service. Fixed in Go 1.24.8 and Go 1.25.2.Community Edition
2.11.1
addresses this CVE
Affected CE versions
>= 2.0, < 2.11.1
Enterprise Edition
2.11.2
addresses this CVE
Affected EE versions
>= 2.0, < 2.11.2
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates