Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
GHSA-8fxq-53rx-ph5fLow· 3.7Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
GHSA-h58c-xccx-75m3Low· 3.4Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
CVE-2026-54162Medium· 4.7Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
GHSA-22w5-2fxg-vrwxLow· 2.6OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
GHSA-q9c5-pp7m-fm2gMedium· 5.3Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
GHSA-rxhg-vcww-2mpwLow· 3.1Fleet: ORDER BY column injection on activity list endpoints
Fleet: ORDER BY column injection on activity list endpoints
CVE-2026-54061Critical· 9.1Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
CVE-2026-49244Medium· 5.9SFTPGo is an open source, event-driven file transfer solution
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…
CVE-2026-49245Low· 3.7SFTPGo is an open source, event-driven file transfer solution
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowin…
CVE-2026-50192MediumKerberos Agent is an open source video (surveillance) management agent
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…
CVE-2026-61711MediumBuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit: Custom frontend could bypass Seccomp/AppArmor
CVE-2026-61712LowBuildKit has a possible runtime DoS via unbounded group parsing
BuildKit has a possible runtime DoS via unbounded group parsing
CVE-2026-52792HighAlgernon is a small self-contained pure-Go web server
Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first rejecting NTFS-equivalent names such as x.lua::$DATA, x.lua.…
CVE-2026-50149Medium· 6.5Contour is a Kubernetes ingress controller using Envoy proxy
Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.v…
GO-2026-6225NoneCredential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
GO-2026-6216NoneCross-forge account takeover on login in codefloe.com/crowci/crow/v6
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
GO-2026-4950NoneAuthorization bypass via double-encoded paths in github.com/valyala/fasthttp
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
CVE-2026-65959Medium· 5.3Vitess is a database clustering system for horizontal scaling of MySQL
Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…
CVE-2026-17106High· 7.8PoCgithub.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)
A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…
GO-2026-6246Noneuniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
GO-2026-6237NoneDenial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
GO-2026-6197NoneWebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6196NoneS3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
GO-2026-6190NoneUnsafe file permission restoration from metadata in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
GO-2026-6189NonePath traversal in serve s3 in github.com/rclone/rclone
Path traversal in serve s3 in github.com/rclone/rclone
GO-2026-6188NoneS3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
GO-2026-6183NoneNil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
GO-2026-6181NoneVerbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq