CVE-2025-22868: Unexpected memory consumption during token parsing in golang.org/x/oauth2

Published Feb 26, 2025
·
Updated

Summary We have encountered a security vulnerability being reported by our scanners for Traefik 2.11.22. - https://security.snyk.io/vuln/SNYK-CHAINGUARDLATEST-TRAEFIK33-9403297

Details It seems to target oauth2/jws library.

PoC No steps to replicate this vulnerability

Impact We have a strict control on security and we always try to stay up-to-date with the fixes received for third-party solutions.

Patches

- https://github.com/traefik/traefik/releases/tag/v2.11.24 - https://github.com/traefik/traefik/releases/tag/v3.3.6 - https://github.com/traefik/traefik/releases/tag/v3.4.0-rc2

Other sources

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

MITRE

Unexpected memory consumption during token parsing in golang.org/x/oauth2

Microsoft

Affected Software

48 affected componentsFixes available
go Jws Go<0.27.0
Google OAuth2
go/github.com/traefik/traefik/v3=3.4.0-rc1
3.4.0-rc2
go/github.com/traefik/traefik/v2<2.11.24
2.11.24
go/github.com/traefik/traefik/v3<3.3.6
3.3.6
go/golang.org/x/oauth2<0.27.0
0.27.0
Microsoft cbl2 moby-engine 24.0.9-17
Microsoft azl3 coredns 1.11.4-6
Microsoft cbl2 node-problem-detector 0.8.17-6
Microsoft cbl2 packer 1.9.5-13
Microsoft azl3 keda 2.14.1-7
Microsoft azl3 moby-engine 25.0.3-13
Microsoft cbl2 telegraf 1.29.4-16
Microsoft azl3 telegraf 1.31.0-10
Microsoft azl3 vitess 19.0.4-7
Microsoft azl3 kubernetes 1.30.10-7
Microsoft cbl2 cert-manager 1.11.2-22
Microsoft azl3 kubernetes 1.30.10-2
Microsoft azl3 azcopy 10.25.1-2
Microsoft azl3 cert-manager 1.12.15-2
Microsoft azl3 node-problem-detector 0.8.20-2
Microsoft azl3 prometheus 2.45.4-8
Microsoft azl3 influxdb 2.7.5-2
Microsoft azl3 packer 1.9.5-6
Microsoft azl3 keda 2.14.1-3
Microsoft azl3 moby-engine 25.0.3-11
Microsoft azl3 containerized-data-importer 1.57.0-13
Microsoft azl3 telegraf 1.31.0-5
Microsoft cbl2 cert-manager 1.11.2-20
Microsoft cbl2 azcopy 10.25.1-3
Microsoft cbl2 moby-engine 24.0.9-15
Microsoft cbl2 packer 1.9.5-10
Microsoft cbl2 vitess 17.0.7-5
Microsoft azl3 coredns 1.11.4-3
Microsoft cbl2 coredns 1.11.1-14
Microsoft cbl2 kubernetes 1.28.4-15
Microsoft cbl2 telegraf 1.29.4-11
Microsoft cbl2 kubernetes 1.28.4-18
Microsoft cbl2 coredns 1.11.1-18
Microsoft cbl2 blobfuse2 2.1.2-8
Microsoft cbl2 vitess 17.0.7-8
Microsoft azl3 containerized-data-importer 1.57.0-14
Microsoft azl3 influxdb 2.7.5-5
Microsoft cbl2 azcopy 10.25.1-5
Microsoft azl3 prometheus 2.45.4-12
Microsoft azl3 packer 1.9.5-9
Microsoft azl3 cert-manager 1.12.15-3
Microsoft azl3 azcopy 10.25.1-4

Remediation

Event History

Feb 26, 2025
CVE Published
via MITRE·03:07 AM
Data Sourced
via MITRE·03:07 AM
DescriptionWeakness
Data Sourced
via Red Hat·04:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:14 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 8, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Apr 18, 2025
Advisory Published
via GitHub·07:32 PM
Data Sourced
via GitHub·07:32 PM
DescriptionSeverityWeaknessAffected Software
Jul 18, 2025
Updated
via GitHub·05:27 PM
DescriptionAffected Software
Jan 12, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-22868?

CVE-2025-22868 has been classified as a medium severity vulnerability due to its potential impact on memory consumption during token parsing.

2

How do I fix CVE-2025-22868?

To fix CVE-2025-22868, it is recommended to update to the latest version of Google OAuth2 that addresses this vulnerability.

3

What type of attacks can exploit CVE-2025-22868?

CVE-2025-22868 can be exploited through the use of malicious malformed tokens that can lead to unexpected memory consumption.

4

Which software is affected by CVE-2025-22868?

CVE-2025-22868 specifically affects Google OAuth2 implementations.

5

What are the potential consequences of CVE-2025-22868?

The potential consequences of CVE-2025-22868 include application crashes or denial of service due to excessive memory usage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203