crossplane-contrib / crossplane-contrib/function-patch-and-transform
Security [High] CVE-2025-58188
- Dominant language
- Go
- Stars
- 46
- Forks
- 41
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 3
Description
Vulnerability Details
ID: https://www.cve.org/CVERecord?id=CVE-2025-58188
Severity: High
Type: go-module
Description: Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
Fix State: fixed
Fix Versions: 1.25.2, 1.24.8
Artifact Paths: /function
More Info: https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI
Contributor guide
No contributing guide indexed for this repository
Research direction
No source file or test is named; start by inspecting the Go module metadata for the /function artifact and checking which dependency provides certificate validation. Confirm the module uses a fixed version, then run the repository’s available tests or vulnerability checks to verify the panic is addressed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100