Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including flatten, min, max, mean, and median, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data structures can lead to a process-level crash due to stack exhaustion. This issue is most relevant in scenarios where Expr is used to evaluate expressions against externally supplied or dynamically constructed environments; cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs; and there are no application-level safeguards preventing deeply nested input data. In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, the resulting panic can be used to reliably crash the application, constituting a denial of service. The issue has been fixed in the v1.17.7 versions of Expr. The patch introduces a maximum recursion depth limit for affected builtin functions. When this limit is exceeded, evaluation aborts gracefully and returns a descriptive error instead of panicking. Additionally, the maximum depth can be customized by users via builtin.MaxDepth, allowing applications with legitimate deep structures to raise the limit in a controlled manner. Users are strongly encouraged to upgrade to the patched release, which includes both the recursion guard and comprehensive test coverage to prevent regressions. For users who cannot immediately upgrade, some mitigations are recommended. Ensure that evaluation environments cannot contain cyclic references, validate or sanitize externally supplied data structures before passing them to Expr, and/or wrap expression evaluation with panic recovery to prevent a full process crash (as a last-resort defensive measure). These workarounds reduce risk but do not fully eliminate the issue without the patch.
CVE-2025-68156
This high-severity CVE scores 7.5 under NVD CVSS v3. EPSS exploit probability: 0.0%, top 88% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.5
- EG Score
- 7.5(medium)
- EPSS
- 31.7%
- KEV
- Not listed
Published
December 16, 2025
Last Modified
March 5, 2026
References (2)
- security-advisories@githubhttps://github.com/expr-lang/expr/pull/870
- security-advisories@githubhttps://github.com/expr-lang/expr/security/advisories/GHSA-cfpf-hrx2-8rv6
Vendor Advisories for CVE-2025-68156(9)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2026:15979Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ceph Storage
- RHSA-2026:5807Red Hat Product SecurityHigh
Red Hat Security Advisory: RHOAI 2.16.4 - Red Hat OpenShift AI
- RHSA-2026:3713Red Hat Product SecurityCritical
Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI
- RHSA-2026:2695Red Hat Product SecurityHigh
Red Hat Security Advisory: RHOAI 2.25.2 - Red Hat OpenShift AI
- RHSA-2026:2572Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.2 security update
- RHSA-2026:2368Red Hat Product SecurityHigh
Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.18.1-2 Update
- RHSA-2026:2106Red Hat Product SecurityHigh
Red Hat Security Advisory: RHOAI 2.25.2 - Red Hat OpenShift AI
- RHSA-2026:1018Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.17.4 security update
- +1 more
Patch Availability(14)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | rhceph/grafana-rhel9:1777566546 | 2026-05-11 | redhat |
| redhat | rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8:1774282202 | 2026-03-25 | redhat |
| redhat | rhoai/odh-model-controller-rhel9:1771378291 | 2026-03-04 | redhat |
| redhat | rhoai/odh-model-registry-rhel9:1770326269 | 2026-02-12 | redhat |
| redhat | rhacm2/acm-grafana-rhel9:1770632254 | 2026-02-11 | redhat |
| redhat | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1770072020 | 2026-02-09 | redhat |
| redhat | rhoai/odh-model-registry-rhel9:1770240648 | 2026-02-05 | redhat |
| redhat | openshift-gitops-1/argocd-rhel9:1768824532 | 2026-01-22 | redhat |
| redhat | openshift-gitops-1/argocd-rhel9:1768881228 | 2026-01-22 | redhat |
| redhat | opentelemetry-collector-0:0.135.0-2.el9_6 | 2026-01-13 | redhat |
| redhat | opentelemetry-collector-0:0.135.0-2.el9_4 | 2026-01-13 | redhat |
| redhat | opentelemetry-collector-0:0.135.0-2.el10_0 | 2026-01-13 | redhat |
| redhat | opentelemetry-collector-0:0.135.0-2.el9_7 | 2025-12-22 | redhat |
| redhat | opentelemetry-collector-0:0.135.0-2.el10_1 | 2025-12-18 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/expr-lang/expr | — | 1.17.7 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(6)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Microsoft MSRCCVE-2025-681562025-12-19
Expr has Denial of Service via Unbounded Recursion in Builtin Functions
- Red HatRHSA-2025:23664IMPORTANT2025-12-16
RHSA-2025:23664 — Important
- Red HatRHSA-2025:23729IMPORTANT2025-12-16
RHSA-2025:23729 — Important
- Red HatRHSA-2026:0512IMPORTANT2025-12-16
RHSA-2026:0512 — Important
- Red HatRHSA-2026:0513IMPORTANT2025-12-16
RHSA-2026:0513 — Important
- Red HatRHSA-2026:0514IMPORTANT2025-12-16
RHSA-2026:0514 — Important
Data Freshness Timeline
(refreshed 11× in last 7d / 43× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 02:00 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-13 06:12 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-11 08:27 UTCEPSS rescore
- 2026-07-09 19:10 UTCEPSS rescore
- 2026-07-08 15:15 UTCEPSS rescore
- 2026-07-07 13:46 UTCEPSS rescore
- 2026-07-06 16:27 UTCEPSS rescore
- 2026-07-06 07:32 UTCOSV refresh
Show 62 moreShow fewer
- 2026-07-06 02:23 UTCEPSS rescore
- 2026-07-05 02:30 UTCEPSS rescore
- 2026-07-05 02:30 UTCEPSS rescore
- 2026-07-04 06:31 UTCEPSS rescore
- 2026-07-04 06:31 UTCEPSS rescore
- 2026-07-01 15:06 UTCEPSS rescore
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-28 14:07 UTCEPSS rescore
- 2026-06-28 14:07 UTCEPSS rescore
- 2026-06-28 04:56 UTCEPSS rescore
- 2026-06-28 04:56 UTCEPSS rescore
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 14:05 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-22 14:25 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-19 19:25 UTCEPSS rescore
- 2026-06-19 19:25 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 19:14 UTCOSV refresh
- 2026-06-17 17:53 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-14 23:18 UTCEPSS rescore
- 2026-06-13 23:00 UTCEPSS rescore
- 2026-06-13 23:00 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 14:00 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:22 UTCEPSS rescore
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-02 20:13 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 17:28 UTCEG score recompute
- 2026-05-29 17:28 UTCVendor advisory
- 2026-05-29 13:44 UTCEPSS rescore
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat · msrc
Same CWE
10 shownCWE-770
Frequently asked(5)
What is CVE-2025-68156?
When was CVE-2025-68156 disclosed?
Is CVE-2025-68156 actively exploited?
What is the CVSS score of CVE-2025-68156?
How do I remediate CVE-2025-68156?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-68156
Is Your Infrastructure Affected by CVE-2025-68156?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.