Improper resource allocation In github.com/open-feature/flagd/flagd

Description

flagd: Multiple Go Runtime CVEs Impact Security and Availability

Summary

In 2025, several vulnerabilities in the Go Standard Library were disclosed, impacting Go-based applications like flagd (the evaluation engine for OpenFeature). These CVEs primarily focus on Denial of Service (DoS) through resource exhaustion and Race Conditions in database handling.

CVE ID
Impacted Package
Severity
Description & Impact on flagd

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions