VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2026-79782Low· 3.1
1mo ago

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.23%via NVD
CVE-2026-79777Low· 2.7
1mo ago

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.33%via NVD
CVE-2026-79664High· 7.4
1mo ago

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on ni…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.27%via NVD
CVE-2026-79783Low· 3.6
1mo ago

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservati…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.18%via NVD
CVE-2026-79781Medium· 6.5
1mo ago

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-sec…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.34%via NVD
CVE-2026-79780Medium· 5.3
1mo ago

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.13%via NVD
CVE-2026-79659High· 7.7
1mo ago

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbit…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.26%via NVD
CVE-2026-79778Medium· 5.3
1mo ago

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connectio…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.32%via NVD
GO-2026-6289None
1mo ago

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

▾ Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6287None
1mo ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/…

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

▾ Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6278None
1mo ago

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

▾ Sunlitgorilla · github.com/gorilla/websocketvia OSV
GO-2026-6277None
1mo ago

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GO-2026-6269None
1mo ago

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6268None
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via OSV
GO-2026-6267None
1mo ago

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6265None
1mo ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6262None
1mo ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

▾ Sunlitopentofu · github.com/opentofu/opentofuvia OSV
CVE-2026-55092High· 7.5
1mo ago

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
CVE-2026-55637High
1mo ago

genieacs-mcp is an MCP server for GenieACS written in Go

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKE…

▾ Twilightgeiserx · github.com/geiserx/genieacs-mcpEPSS 0.26%via NVD
CVE-2026-55582High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShel…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.27%via NVD
CVE-2026-55581High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.45%via NVD
CVE-2026-55580High
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bi…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.20%via NVD
CVE-2026-32637Medium
1mo ago

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarb…

▾ Sunlitvmware-tanzu · github.com/vmware-tanzu/veleroEPSS 0.54%via NVD
GHSA-vx2m-jpxr-xv7wMedium· 5.3
1mo ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-w8j7-39hp-8x59Medium
1mo ago

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-4ph6-mjv7-3fq6Low
1mo ago

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-w67g-5rqw-f597Medium
1mo ago

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

▾ Sunlitgorilla · github.com/gorilla/websocketvia GHSA
CVE-2026-55477High· 7.2
1mo ago

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

▾ Twilightmhsanaei · github.com/mhsanaei/3x-ui/v3EPSS 0.61%via GHSA
CVE-2026-45404Medium
1mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe fo…

▾ Sunlitotel · go.opentelemetry.io/otel/bridge/opentracingEPSS 0.14%via NVD
CVE-2026-71494Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a…

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.50%via NVD
CVEs tagged “go” — page 10 · VulnSea