Intel

AIKIDO-2025-10169

golang.org/x/oauth2 is vulnerable to Unlimited Resource Consumption

Unlimited Resource ConsumptionCVE-2025-22868 Published Mar 20, 2025

87

High Risk

This Affects:

GOgolang.org/x/oauth2
0.1.0 - 0.26.0
Fixed in 0.27.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Unlimited Resource Consumption where an attacker can pass a malformed token, causing excessive memory consumption during parsing. This can lead to a denial-of-service (DoS) condition by exhausting system resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

golang.org/x/oauth2 is vulnerable to Unlimited Resource Consumption in versions 0.1.0 - 0.26.0.

How to fix this

Upgrade the golang.org/x/oauth2 library to the patch version.