CVE-2025-22868
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
- T
Tim Bastin detected CVE-2025-22868 with a risk of 2.12
System updated the risk assessment from 2.12 to 1.41
System recalculated raw risk assessment
System updated the risk assessment from 1.41 to 4.25
System recalculated raw risk assessment
- T
Tim Bastin detected CVE-2025-22868 with scanner: container-scanning
- T
Tim Bastin created a ticket for CVE-2025-22868
Everything after this entry will be synced with the external system. The ticket can be found at https://gitlab.opencode.de/open-code/badgebackend/badge-api/-/issues/11
System updated the risk assessment from 4.25 to 1.15
System recalculated raw risk assessment
System updated the risk assessment from 1.15 to 2.12
System recalculated raw risk assessment
System detected CVE-2025-22868 with a risk of 4.25
System detected CVE-2025-22868 with scanner: sca
System created a ticket for CVE-2025-22868
Everything after this entry will be synced with the external system. The ticket can be found at https://gitlab.opencode.de/open-code/badgebackend/badge-api/-/issues/12
System created a ticket for CVE-2025-22868
Everything after this entry will be synced with the external system. The ticket can be found at https://gitlab.opencode.de/open-code/badgebackend/badge-api/-/issues/13
System updated the risk assessment from 4.25 to 2.12
System recalculated raw risk assessment
Add a comment
Affected component
golang.org/x/oauth2