Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
Malformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq
GSS authentication completes without mutual proof in github.com/lib/pq
GO-2026-6143Nonenetfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
GO-2026-6117NonePocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
CVE-2026-56867NoneMultiple denial of service vulnerabilities in rsc.io/pdf and forks
Multiple denial of service vulnerabilities in rsc.io/pdf and forks
GO-2026-6113NoneOpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
GO-2026-6106NoneCloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
GO-2026-6105NoneKite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
GO-2026-6094NoneJSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
GO-2026-6093NoneAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
CVE-2026-69160Medium· 6.5OpenList a file list program that supports multiple storage
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator b…
CVE-2026-63328MediumTrivy is a security scanner
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to i…
CVE-2026-73502Medium· 5.3kin-openapi is a Go project for handling OpenAPI files
kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/…
CVE-2026-62684Low· 2.7File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…
CVE-2026-50138High· 8.1goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…
CVE-2026-50139Medium· 5.9goshs is a SimpleHTTPServer written in Go
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…
GHSA-mpwr-8vm7-h73fMediumpackage pkcs12: Authentication bypass in Decode functions
package pkcs12: Authentication bypass in Decode functions
GHSA-fhgh-wq4q-r37xHigh· 7.8uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
CVE-2026-64859Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…
CVE-2026-64868High· 7.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…
CVE-2026-64866MediumNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…
CVE-2026-71479Critical· 9.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…
CVE-2026-64865MediumNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…
CVE-2024-58375High· 7.5⚖ disputedOpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive m…
CVE-2026-74796Medium· 6.1OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…
CVE-2026-74797Low· 3.1OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling …
CVE-2025-71405Mediumchi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary ho…