Description
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
Published: 2022-08-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-52466 Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
Ubuntu USN Ubuntu USN USN-6038-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-6038-2 Go vulnerabilities
History

Fri, 06 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00132}

epss

{'score': 0.00114}


Sun, 08 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat acm
Redhat multicluster Engine
CPEs cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat acm
Redhat multicluster Engine

Mon, 19 Aug 2024 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat acm
Redhat multicluster Engine

Subscriptions

Golang Go
Redhat Acm Ceph Storage Container Native Virtualization Devtools Enterprise Linux Multicluster Engine Openshift Api Data Protection Openshift Custom Metrics Autoscaler Openshift Data Foundation Openshift Secondary Scheduler Openstack Rhmt Serverless Service Mesh
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-03-06T17:44:24.600Z

Reserved: 2022-05-12T00:00:00.000Z

Link: CVE-2022-30635

cve-icon Vulnrichment

Updated: 2024-08-03T06:56:13.235Z

cve-icon NVD

Status : Modified

Published: 2022-08-10T20:15:42.640

Modified: 2026-03-06T18:16:14.177

Link: CVE-2022-30635

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-07-12T00:00:00Z

Links: CVE-2022-30635 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses