Vulnerability Report: GO-2025-4087
- GHSA-fj2x-735w-74vq
- Affects: github.com/consensys/gnark-crypto
- Published: Nov 05, 2025
Unchecked memory allocation during vector deserialization in github.com/consensys/gnark-crypto
For detailed information about this vulnerability, visit https://github.com/Consensys/gnark-crypto/security/advisories/GHSA-fj2x-735w-74vq.
Affected Packages
-
PathVersionsSymbols
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
-
from v0.9.1 before v0.18.1, from v0.19.0 before v0.19.2
Aliases
References
- https://github.com/Consensys/gnark-crypto/security/advisories/GHSA-fj2x-735w-74vq
- https://github.com/Consensys/gnark-crypto/commit/2e7bf9190a0aac896eeec3876c87c77a35661be7
- https://github.com/Consensys/gnark-crypto/pull/759
- https://github.com/Consensys/gnark-crypto/commit/2e7bf9190a0aac896eeec3876c87c77a35661be7
- https://vuln.go.dev/ID/GO-2025-4087.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.