CVE-2025-22865 Information

Description

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

Reference

https://go.dev/cl/643098 https://go.dev/issue/71216 https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ https://pkg.go.dev/vuln/GO-2025-3421

Share on: