Home / Security / Advisories / NTAP-20260703-0006
NTAP-20260703-0006 — January 2026 Golang Vulnerabilities in NetApp Products
Published 2026-07-03 · Updated 2026-09-16 · Status: Interim · Exploitation: Public · Severity: HIGH 7.8 · ONTAP affected: Yes
Product family: Astra Control · Other NetApp products · NetApp Console / BlueXP · ONTAP | ONTAP-relevant | highest CVSS: 7.8
CVEs in this advisory
- CVE-2025-61728 — MEDIUM · CVSS 6.5 · site index
- CVE-2025-61730 — MEDIUM · CVSS 5.3 · site index
- CVE-2025-61731 — HIGH · CVSS 7.8 · site index
- CVE-2025-68119 — HIGH · CVSS 7.0 · site index
What the CVE records say
CVE-2025-61728 — archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
CVE-2025-61730 — During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.
CVE-2025-61731 — Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
CVE-2025-68119 — Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). <br><br> ONTAP tools for VMware vSphere 10:<br> Affected only by CVE-2025-61730.
Affected products
- Astra Control Center
- Astra Control Provisioner
- FAS/AFF BIOS - A900/9500
- NetApp Console Agent
- NetApp Console Agent OVA
- ONTAP tools for VMware vSphere 10
References
- https://pkg.go.dev/vuln/GO-2026-4337 ↗
- https://pkg.go.dev/vuln/GO-2026-4338 ↗
- https://pkg.go.dev/vuln/GO-2026-4339 ↗
- https://pkg.go.dev/vuln/GO-2026-4340 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026