The Go Project disclosed CVE-2025-61726, a denial-of-service flaw in the standard library's net/url handling that can be triggered through net/http.Request.ParseForm. The bug stems from the lack of a limit on query parameter counts, allowing attackers to submit URL-encoded forms with many unique parameters and drive excessive memory consumption. The issue affects Go releases before 1.24.12 and 1.25.x before 1.25.6, and is tracked in Go issue #77101 and Go advisory GO-2026-4341.
Red Hat subsequently shipped Important security updates for multiple products bundling vulnerable Go components, most notably grafana-pcp across RHEL 8, RHEL 9, and RHEL 10 channels, as well as golang-github-openprinting-ipp-usb on RHEL 10. Several advisories bundled fixes for related Go flaws, including CVE-2025-61729 in crypto/x509 and **CVE-2025-68121incrypto/tls, with updated packages released for x86_64, aarch64, ppc64le, and s390x` architectures across standard, SAP, AUS, EUS, and Extended Life Cycle offerings.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:3977 for golang-github-openprinting-ipp-usb on RHEL 10.0 channels, releasing ipp-usb version 0.9.27-3.el10_0.2. The update fixes Go vulnerabilities CVE-2025-61726 and CVE-2025-68121.
Red Hat published RHSA-2026:3822 for grafana-pcp on RHEL 9.0 Update Services for SAP Solutions, releasing version 3.2.0-5.el9_0. The update addresses CVE-2025-61726 and CVE-2025-61729.
Red Hat published RHSA-2026:3820 for grafana-pcp on RHEL 9.2 channels, releasing version 5.1.1-4.el9_2. The update addresses CVE-2025-61726 and CVE-2025-61729.
Red Hat published RHSA-2026:3817 for grafana-pcp on RHEL 9.6 channels, releasing version 5.1.1-12.el9_6. The update fixes CVE-2025-61726, CVE-2025-61729, and CVE-2025-68121.
Red Hat published RHSA-2026:3816 for grafana-pcp on RHEL 10.0 channels, releasing version 5.2.2-4.el10_0. The update fixes CVE-2025-61726, CVE-2025-61729, and CVE-2025-68121.
Red Hat published RHSA-2026:3187 for grafana-pcp on RHEL 8, releasing version 5.1.1-12.el8_10. The update remediates bundled Go vulnerabilities CVE-2025-61726 and CVE-2025-68121.
Red Hat published RHSA-2026:3035 for grafana-pcp on RHEL 10, releasing version 5.3.0-2.el10_1. The advisory addresses CVE-2025-61726, CVE-2025-61729, and CVE-2025-68121 across multiple RHEL 10 variants and architectures.
Red Hat published RHSA-2026:3040 for grafana-pcp on RHEL 9, releasing version 5.1.1-12.el9_7. The update fixes bundled Go vulnerabilities including CVE-2025-61726, CVE-2025-61729, and CVE-2025-68121.
The Go Project published the CVE record for CVE-2025-61726 and the Go vulnerability database entry GO-2026-4341. Both describe uncontrolled resource consumption in net/url query parsing that can be triggered through large URL-encoded forms handled by net/http.Request.ParseForm.
Go addressed CVE-2025-61726, a memory exhaustion flaw caused by unlimited query parameter parsing in net/url. The fix applies to versions before 1.24.12 and 1.25.x before 1.25.6, and is referenced by Go change list 736712 and issue 77101.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecve.org
Open sourcego.dev
Open sourcegroups.google.com
Open sourcego.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.