Vulnerability Report: GO-2025-4245
- CVE-2025-68156, GHSA-cfpf-hrx2-8rv6
- Affects: github.com/expr-lang/expr
- Published: Dec 22, 2025
Expr has Denial of Service via Unbounded Recursion in Builtin Functions in github.com/expr-lang/expr
For detailed information about this vulnerability, visit https://github.com/expr-lang/expr/security/advisories/GHSA-cfpf-hrx2-8rv6.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/expr-lang/expr/security/advisories/GHSA-cfpf-hrx2-8rv6
- https://github.com/expr-lang/expr/pull/870
- https://vuln.go.dev/ID/GO-2025-4245.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.