VulnSea

Tagged “go”

CVEs tagged go, newest first.

1674 CVEsRSS

CVE-2026-61687High· 7.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet · hatchetvia NVD
GHSA-xwmw-prc4-v3crHigh· 8.8
3d ago

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-pr6h-vr44-xq8jMedium· 5.3
3d ago

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

Sunlitobot-platform · github.com/obot-platform/obotvia OSV
GHSA-jgh3-fggc-mcpmHigh· 7.6
3d ago

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

Twilightobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-63458High· 7.1
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

Twilightperses · persesEPSS 0.30%via NVD
CVE-2026-63445High· 7.1
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2026-63199High· 8.3
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

Twilightperses · github.com/perses/persesEPSS 0.27%via NVD
CVE-2026-63406Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

Twilightanycable · github.com/anycable/anycableEPSS 0.24%via NVD
CVE-2026-63405Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

Twilightanycable · github.com/anycable/anycableEPSS 0.17%via NVD
CVE-2026-61833High· 8.1
3d ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

Twilightzot · zotregistry.dev/zot/v2EPSS 0.43%via NVD
CVE-2026-81505High· 7.1PoC
3d ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.34%via NVD
CVE-2026-61794Medium· 6.8
3d ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.33%via NVD
CVE-2026-61795Medium· 6.8
3d ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validate…

Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.33%via NVD
CVE-2026-61672High· 7.1
3d ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assume…

Twilightprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.20%via NVD
CVE-2026-77339Medium· 5.1PoC
3d ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.21%via NVD
CVE-2026-58197High· 8.8PoC
3d ago

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission pro…

Midnightstacklok · github.com/stacklok/toolhiveEPSS 0.36%via NVD
CVE-2026-61682Critical· 9.9
3d ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

Midnightkcp-dev · kcpEPSS 0.28%via NVD
CVE-2026-77281Medium· 6.5
4d ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

Sunlitcaddyserver · caddyEPSS 0.36%via NVD
CVE-2026-55061Low· 1.0
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…

Sunlituniget-org · cliEPSS 0.12%via NVD
CVE-2026-55062High· 8.4
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

Twilightuniget-org · cliEPSS 0.13%via NVD
CVE-2026-50285High· 7.5PoC
4d ago

Pomerium is an identity and context-aware access proxy

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…

Midnightpomerium · pomeriumEPSS 0.65%via NVD
CVE-2026-54495Medium· 4.3
4d ago

The OpenFeature Operator allows users to expose feature flags to applications

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…

Sunlitopen-feature · open-feature-operatorEPSS 0.23%via NVD
CVE-2026-50158High· 7.7
4d ago

yutu is an AI-powered toolkit for managing and growing YouTube channels

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…

Twilighteat-pray-ai · yutuEPSS 0.17%via NVD
CVE-2026-50125High· 7.5
4d ago

MKP is a Model Context Protocol server for Kubernetes

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitByt…

TwilightStacklokLabs · mkpEPSS 0.41%via NVD
CVE-2026-47252Critical· 9.0PoC
4d ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brav…

Abyssaljulien040 · anyqueryEPSS 0.45%via NVD
GO-2026-6449None
5d ago

Komari: Management Interface CSRF in github.com/komari-monitor/komari

Komari: Management Interface CSRF in github.com/komari-monitor/komari

Sunlitkomari-monitor · github.com/komari-monitor/komarivia OSV
CVE-2026-81871Medium· 6.3
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

Sunlitopen-telemetry · opentelemetry-goEPSS 0.20%via NVD
CVE-2026-81870Low· 2.0PoC
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-82399High· 7.5PoC
5d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…

Midnightcoredns · corednsEPSS 0.61%via NVD
CVE-2026-86003High· 7.5
5d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

Twilightcoredns · corednsEPSS 0.44%via NVD
CVEs tagged “go” · VulnSea