expr-lang CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

expr-lang 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to expr-lang, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-68156 Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing [email protected] 7.5 0.38% 2025-12-16 2026-03-05
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence