crossplane-contrib / crossplane-contrib/function-patch-and-transform

Security [High] CVE-2025-58188

Open
#263 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
46
Forks
41
Avg merge
1d 10h
Merged PRs (30d)
3

Description

Vulnerability Details

ID: https://www.cve.org/CVERecord?id=CVE-2025-58188
Severity: High
Type: go-module
Description: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
Fix State: fixed
Fix Versions: 1.25.2, 1.24.8
Artifact Paths: /function
More Info: https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file or test is named; start by inspecting the Go module metadata for the /function artifact and checking which dependency provides certificate validation. Confirm the module uses a fixed version, then run the repository’s available tests or vulnerability checks to verify the panic is addressed.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.