https://seclists.org/oss-sec/2025/q4/249: Go 1.25.5 and Go 1.24.11 aleased - fix CVE-2025-61729 & CVE-2025-61727
Published Dec 5, 2025
·Updated
Affected Software
1 affected component
golang/go
Frequently Asked Questions
1
What is the severity of CVE-2025-61729?
CVE-2025-61729 has a critical severity level due to excessive resource consumption.
2
How do I fix CVE-2025-61727?
To fix CVE-2025-61727, upgrade to Go version 1.25.5 or 1.24.11 immediately.
3
What impact does CVE-2025-61729 have on applications?
CVE-2025-61729 can cause applications to become unresponsive by consuming excessive resources.
4
When were the Go versions that fixed CVE-2025-61729 and CVE-2025-61727 released?
The fixed versions were released on December 5, 2025.
5
Is it mandatory to update to Go version 1.25.5 or 1.24.11 due to these vulnerabilities?
Yes, it is recommended to update to avoid potential exploitation of these vulnerabilities.