Home / Security / Advisories / NTAP-20260703-0007
NTAP-20260703-0007 — October 2025 Golang Vulnerabilities in NetApp Products
Published 2026-07-03 · Updated 2026-09-23 · Status: Interim · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: Astra Control · ONTAP · Other NetApp products · NetApp Console / BlueXP | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2025-58183 — MEDIUM · CVSS 4.3 · site index
- CVE-2025-58185 — MEDIUM · CVSS 5.3 · site index
- CVE-2025-58186 — MEDIUM · CVSS 5.3 · site index
- CVE-2025-58188 — HIGH · CVSS 7.5 · site index
- CVE-2025-58189 — MEDIUM · CVSS 5.3 · site index
- CVE-2025-61723 — HIGH · CVSS 7.5 · site index
- CVE-2025-61724 — MEDIUM · CVSS 5.3 · site index
- CVE-2025-61725 — HIGH · CVSS 7.5 · site index
What the CVE records say
CVE-2025-58183 — tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
CVE-2025-58185 — Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-58186 — Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.
CVE-2025-58188 — Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.
CVE-2025-58189 — When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-61723 — The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-61724 — The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-61725 — The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or Denial of Service (DoS).
Affected products
- Astra Control Center
- ONTAP tools for VMware vSphere 10
- Astra Control Provisioner
- FAS/AFF BIOS - A900/9500
- NetApp Console Agent
- NetApp Console Agent OVA
References
- https://pkg.go.dev/vuln/GO-2025-4006 ↗
- https://pkg.go.dev/vuln/GO-2025-4008 ↗
- https://pkg.go.dev/vuln/GO-2025-4009 ↗
- https://pkg.go.dev/vuln/GO-2025-4011 ↗
- https://pkg.go.dev/vuln/GO-2025-4012 ↗
- https://pkg.go.dev/vuln/GO-2025-4013 ↗
- https://pkg.go.dev/vuln/GO-2025-4014 ↗
- https://pkg.go.dev/vuln/GO-2025-4015 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026