PT-2025-39916 · Go-F3 · Go-F3

Lgprbs

·

Published

2025-09-29

·

Updated

2025-10-27

·

CVE-2025-59941

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions go-f3 versions 0.8.8 and below
Description go-f3’s justification verification caching mechanism improperly caches verification results without considering the message context. An attacker can bypass justification verification by submitting a valid message with a correct justification and then reusing the same cached justification in contexts where it would normally be invalid. The cached verification does not validate the relationship between the justification and the specific message context. Exploitation requires significant computational power (350+ TiB) and coordinated timing to impact a substantial portion of the network.
Recommendations Upgrade to go-f3 version 0.8.9 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-59941
GHSA-7PQ9-RF9P-WCRF
GO-2025-3989
OPENSUSE-SU-2025:15666-1
SUSE-SU-2025:3799-1

Affected Products

Go-F3