Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2025-61726

CVE-2025-61726

None
Open
TLP:CLEAR

Memory exhaustion in query parameter parsing in net/url

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.

Details

EPSS Score
1.94%

78.4th percentile

Confidence
90%
Published
Jan 28, 2026
Last Modified
Aug 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.