Impact
CVE-2025-61726 affects Go's standard library net/url package. The Go vulnerability report describes excessive memory consumption when applications parse large URL-encoded forms or many unique query parameters on affected Go releases [S1]. NVD maps the issue to CWE-770 with high availability impact [S3].
What changed in Go
Go fixed this issue in Go 1.24.12 and Go 1.25.6. Services built with an affected Go release should be rebuilt with one of those releases or a newer supported Go release [S1][S2].
Covered by FixVibe
FixVibe's GitHub repository scans flag repositories that build with an affected Go release and parse query parameters or URL-encoded forms through the affected Go standard-library APIs [S1].
What evidence customers see
A FixVibe report identifies the affected Go version evidence, the source file and line where the parsing path appears, and the fixed Go release line.
Remediation
Upgrade the Go toolchain used for the deployed service to Go 1.24.12, Go 1.25.6, or a newer supported Go release [S1][S2]. Rebuild and redeploy binaries and container images from clean caches. Keep explicit request body, header, and parameter-count limits around form and query parsing, then rerun the FixVibe GitHub repo scan.
