CVE-2025-22868: Unexpected memory consumption during token parsing in golang.org/x/oauth2

Description

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Classification

CVE ID: CVE-2025-22868

Problem Types

CWE-1286: Improper Validation of Syntactic Correctness of Input

Affected Products

Vendor: golang.org/x/oauth2

Product: golang.org/x/oauth2/jws

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.17% (probability of being exploited)

EPSS Percentile: 34.93% (scored less or equal to compared to others)

EPSS Date: 2025-03-27 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-22868
https://go.dev/cl/652155
https://go.dev/issue/71490
https://pkg.go.dev/vuln/GO-2025-3488

Timeline