Uncaught Exception Affecting std/crypto/dsa package, versions <1.12.11>=1.13.0-0 <1.13.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
4.69% (91st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-STDCRYPTODSA-14564551
  • published6 Jan 2026
  • disclosed24 May 2022
  • creditDaniel M, ragona

Introduced: 24 May 2022

CVE-2019-17596  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade std/crypto/dsa to version 1.12.11, 1.13.2 or higher.

Overview

std/crypto/dsa is a Go standard library package std/crypto/dsa

Affected versions of this package are vulnerable to Uncaught Exception.

Go Vulnerability Report:
via the dsa.Verify function. An attacker can cause a panic and potentially crash the application by submitting a crafted DSA public key or a malicious X.509 certificate chain. This can be triggered through a crypto/tls connection, by delivering malformed certificates to clients or servers that verify client certificates, or by invoking certificate signature checks in affected cryptographic processes.

CVSS Base Scores

version 4.0
version 3.1