Microsoft Security Response Center guidance
See the Microsoft Security Update Guide for the update that applies to your product.
Vulnerability intelligence
CVE-2025-61726 and is rated High severity with a CVSS score of 7.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
See the Microsoft Security Update Guide for the update that applies to your product.
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.