{"id":"CVE-2026-33818","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-33818","summary":"Enforce maximum recursion depth in encoding/asn1","details":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.","published":"2026-08-13T21:43:54Z","modified":"2026-08-14T09:41:58.447809317Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"stdlib","fixedVersion":"1.25.13"}],"fix":null,"references":[{"type":"REPORT","url":"https://go.dev/issue/80405"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/94pEornpRlI"},{"type":"FIX","url":"https://go.dev/cl/814980"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T09:41:58.447809317Z"}}