VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

GHSA-8fxq-53rx-ph5fLow· 3.7
1mo ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

▾ Sunlitcoder · github.com/coder/coder/v2via GHSA
GHSA-h58c-xccx-75m3Low· 3.4
1mo ago

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

▾ Sunlitcoder · github.com/coder/coder/v2via GHSA
CVE-2026-54162Medium· 4.7
1mo ago

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

▾ Sunlitalexandre-daubois · github.com/alexandre-daubois/embervia GHSA
GHSA-22w5-2fxg-vrwxLow· 2.6
1mo ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

▾ Sunlitopentofu · github.com/opentofu/opentofuvia OSV
GHSA-q9c5-pp7m-fm2gMedium· 5.3
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
GHSA-rxhg-vcww-2mpwLow· 3.1
1mo ago

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
CVE-2026-54061Critical· 9.1
1mo ago

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.58%via GHSA
CVE-2026-49244Medium· 5.9
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.45%via NVD
CVE-2026-49245Low· 3.7
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowin…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.25%via NVD
CVE-2026-50192Medium
1mo ago

Kerberos Agent is an open source video (surveillance) management agent

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…

▾ Sunlitkerberos-io · github.com/kerberos-io/agent/machineryEPSS 0.42%via NVD
CVE-2026-61711Medium
1mo ago

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.47%via OSV
CVE-2026-61712Low
1mo ago

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.53%via OSV
CVE-2026-52792High
1mo ago

Algernon is a small self-contained pure-Go web server

Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first rejecting NTFS-equivalent names such as x.lua::$DATA, x.lua.…

▾ Twilightxyproto · github.com/xyproto/algernonEPSS 0.63%via NVD
CVE-2026-50149Medium· 6.5
1mo ago

Contour is a Kubernetes ingress controller using Envoy proxy

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.v…

▾ Sunlitprojectcontour · github.com/projectcontour/contourEPSS 0.18%via NVD
GO-2026-6225None
1mo ago

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

▾ Sunlitchrismellard · github.com/chrismellard/docker-credential-acr-envvia OSV
GO-2026-6216None
1mo ago

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

▾ Sunlitcrowci · codefloe.com/crowci/crow/v6via OSV
GO-2026-4950None
1mo ago

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

▾ Sunlitvalyala · github.com/valyala/fasthttpvia OSV
CVE-2026-65959Medium· 5.3
1mo ago

Vitess is a database clustering system for horizontal scaling of MySQL

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() wi…

▾ Sunlitvitess · vitess.io/vitessEPSS 0.43%via NVD
CVE-2026-17106High· 7.8PoC
1mo ago

github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)

A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…

▾ MidnightRed Hat · Red Hat Edge Manager 1.2EPSS 0.44%via CSAF
GO-2026-6246None
1mo ago

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

▾ Sunlituniget-org · gitlab.com/uniget-org/clivia OSV
GO-2026-6237None
1mo ago

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

▾ Sunlitinsomniacslk · github.com/insomniacslk/dhcpvia OSV
GO-2026-6197None
1mo ago

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6196None
1mo ago

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6190None
1mo ago

Unsafe file permission restoration from metadata in github.com/rclone/rclone

Unsafe file permission restoration from metadata in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6189None
1mo ago

Path traversal in serve s3 in github.com/rclone/rclone

Path traversal in serve s3 in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6188None
1mo ago

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6183None
1mo ago

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
GO-2026-6181None
1mo ago

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

▾ Sunlitrclone · github.com/rclone/rclonevia OSV
CVE-2026-56874None
1mo ago

Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq

Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
CVE-2026-56873None
1mo ago

Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq

Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
CVEs tagged “go” — page 12 · VulnSea