CVE-2025-11065 - CVE House
Back to Database
Status published Medium CVE-2025-11065

Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure

Vulnerability Description

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11065

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

OpenShift Pipelines, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 4, Red Hat Certification for Red Hat Enterprise Linux 8, Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, Red Hat OpenShift distributed tracing 3, Red Hat OpenShift GitOps, Red Hat Trusted Application Pipeline, Red Hat Trusted Artifact Signer, Zero Trust Workload Identity Manager - Tech Preview
Vulnerable Versions:
0

Timeline

Official Publish: January 26th, 2026
Last Modified: June 29th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)