PT-2025-42407 · Debian+2 · Debian+2

CVE-2025-11065

·

Published

2025-01-01

·

Updated

2026-06-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions github.com/go-viper/mapstructure/v2 (affected versions not specified)
Description A flaw exists in the field processing component that utilizes the mapstructure.WeakDecode() function. The issue stems from improper neutralization of output data sent to logs, where detailed error messages may leak sensitive input values. This occurs when malformed user-supplied data is processed within security-critical contexts, potentially allowing a remote attacker to gain access to confidential information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-75351
AZL-75369
AZL-75372
AZL-75375
AZL-75389
AZL-75402
AZL-75407
AZL-75410
AZL-75413
AZL-75416
AZL-75419
AZL-75425
AZL-75428
AZL-75434
AZL-75440
AZL-75449
AZL-75452
AZL-75458
AZL-75473
AZL-75476
AZL-75479
AZL-75488
AZL-75491
AZL-75497
AZL-75500
AZL-75524
AZL-75527
AZL-75530
AZL-75545
AZL-75548
AZL-75551
AZL-75554
AZL-75557
AZL-75560
AZL-75564
AZL-75573
AZL-75576
AZL-75579
AZL-75582
BDU:2025-15587
CLEANSTART-2026-KC83705
CLEANSTART-2026-NV37937
CLEANSTART-2026-QU88766
CLEANSTART-2026-VD70282
CLEANSTART-2026-YF74364
CLEANSTART-2026-ZI02697
CVE-2025-11065
GHSA-2464-8J7C-4CJM
GHSA-86RF-68F4-2CPH
GO-2025-3900
OPENSUSE-SU-2025:15610-1
OPENSUSE-SU-2025:15631-1
OPENSUSE-SU-2025:15724-1
OPENSUSE-SU-2025:20073-1
OPENSUSE-SU-2025:20117-1
OPENSUSE-SU-2026:10232-1
OPENSUSE-SU-2026:20386-1
OPENSUSE-SU-2026:20654-1
OPENSUSE-SU-2026:20798-1
SUSE-SU-2025:21137-1
SUSE-SU-2025:4121-1
SUSE-SU-2025:4444-1
SUSE-SU-2025:4446-1
SUSE-SU-2025:4457-1
SUSE-SU-2025:4458-1
SUSE-SU-2025:4479-1
SUSE-SU-2025:4482-1
SUSE-SU-2025_21137-1
SUSE-SU-2025_4121-1
SUSE-SU-2026:0777-1
SUSE-SU-2026:20904-1

Affected Products

Debian
Red Os
Golang-Github-Go-Viper-Mapstructure