CVE-2025-11065
Unknown
Unknown - Not Provided
Information Disclosure via WeakDecode in go-viper/mapstructure Field Processing
Publication date: 2026-01-26
Last updated on: 2026-02-03
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| unknown_vendor | mapstructure | 2.4.0 |
| unknown_vendor | mapstructure | to 2.4.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |