๐Ÿ” CVE Alert

CVE-2025-11065

MEDIUM 5.3

Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.

CWE CWE-209
Published Jan 26, 2026
Last Updated Feb 3, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Red Hat / OpenShift Pipelines
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Management for Kubernetes 2
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Certification for Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Certification Program for Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat OpenShift AI (RHOAI)
All versions affected
Red Hat / Red Hat OpenShift AI (RHOAI)
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat OpenShift distributed tracing 3
All versions affected
Red Hat / Red Hat OpenShift GitOps
All versions affected
Red Hat / Red Hat OpenShift GitOps
All versions affected
Red Hat / Red Hat Trusted Application Pipeline
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Red Hat Trusted Artifact Signer
All versions affected
Red Hat / Zero Trust Workload Identity Manager - Tech Preview
All versions affected
Red Hat / Zero Trust Workload Identity Manager - Tech Preview
All versions affected
Red Hat / Zero Trust Workload Identity Manager - Tech Preview
All versions affected
Red Hat / Zero Trust Workload Identity Manager - Tech Preview
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-11065 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2391829 github.com: https://github.com/go-viper/mapstructure/commit/742921c9ba2854d27baa64272487fc5075d2c39c github.com: https://github.com/go-viper/mapstructure/security/advisories/GHSA-2464-8j7c-4cjm