Vulnerability Report: GO-2025-4021
- CVE-2025-59836, GHSA-4p3p-cr38-v5xp
- Affects: github.com/siderolabs/omni
- Published: Nov 05, 2025
- Unreviewed
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni
For detailed information about this vulnerability, visit https://github.com/siderolabs/omni/security/advisories/GHSA-4p3p-cr38-v5xp or https://nvd.nist.gov/vuln/detail/CVE-2025-59836.
Affected Modules
-
PathGo Versions
-
before v1.0.2, from v1.1.0-beta.0 before v1.1.5
Aliases
References
- https://github.com/siderolabs/omni/security/advisories/GHSA-4p3p-cr38-v5xp
- https://nvd.nist.gov/vuln/detail/CVE-2025-59836
- https://github.com/siderolabs/omni/commit/1396083f766a1b0380e9949968d7fc17b7afecaa
- https://github.com/siderolabs/omni/commit/1fd954af64985a8b3dbf5b11deddbf7cd953f5ae
- https://vuln.go.dev/ID/GO-2025-4021.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.