CVE-2025-61726 Golang Vulnerability in NetApp Products
Summary
Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.12 and 1.25.0 prior to 1.25.6 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent, ONTAP tools for VMware vSphere 10, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
What this means
In plain English
Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.12 and 1.25.0 prior to 1.25.6 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent, ONTAP tools for VMware vSphere 10, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time. Successful exploitation can interrupt the affected service or exhaust resources, reducing availability until the component recovers.
Vulnerable items
- Astra Control Center
- NetApp Console Agent
- ONTAP tools for VMware vSphere 10 — NetApp ONTAP is the storage operating system used across NetApp enterprise storage systems.
- Trident Protect
Recommended action
Primary action: update to a vendor-listed fixed release: NetApp Console Agent: 4.9.0, Trident Protect: 26.02. Vendor mitigation: Update affected NetApp products to a fixed release: NetApp Console Agent: 4.9.0, Trident Protect: 26.02. Astra Control Center has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice. Trident Protect: Fixed in 26.02.
Rewritten locally from the scraped official advisory data above; no generative API is used. The vendor advisory is authoritative.
- 1.24.12
- 1.25.0
- 1.25.6
Official advisory · high-confidence parse· fetched 11 hours ago·verify at source
- NetApp Console Agent: 4.9.0
- Trident Protect: 26.02
Official advisory · high-confidence parse· fetched 11 hours ago·verify at source
Mitigation checklist
- Update affected NetApp products to a fixed release: NetApp Console Agent: 4.9.0, Trident Protect: 26.02.
- Astra Control Center has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
- Trident Protect: Fixed in 26.02.
Official advisory · high-confidence parse· fetched 11 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.