VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-56872None
1mo ago

Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq

Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
CVE-2026-56871None
1mo ago

Malformed backend frame length causes panic in github.com/lib/pq

Malformed backend frame length causes panic in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
CVE-2026-56870None
1mo ago

Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq

Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
CVE-2026-56869None
1mo ago

Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram

Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram

▾ Sunlitlib · github.com/lib/pqvia OSV
CVE-2026-56868None
1mo ago

GSS authentication completes without mutual proof in github.com/lib/pq

GSS authentication completes without mutual proof in github.com/lib/pq

▾ Sunlitlib · github.com/lib/pqvia OSV
GO-2026-6143None
1mo ago

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GO-2026-6117None
1mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check tha…

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia OSV
CVE-2026-56867None
1mo ago

Multiple denial of service vulnerabilities in rsc.io/pdf and forks

Multiple denial of service vulnerabilities in rsc.io/pdf and forks

▾ Sunlitpdf · rsc.io/pdfvia OSV
GO-2026-6113None
1mo ago

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenListvia OSV
GO-2026-6106None
1mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

▾ Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6105None
1mo ago

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

▾ Sunlitzxh326 · github.com/zxh326/kitevia OSV
GO-2026-6094None
1mo ago

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

▾ Sunlitgoogle · github.com/google/cel-govia OSV
GO-2026-6093None
1mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

▾ Sunlitaws · github.com/aws/aws-cdk-go/awscdkvia OSV
CVE-2026-69160Medium· 6.5
1mo ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator b…

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4EPSS 0.40%via NVD
CVE-2026-63328Medium
1mo ago

Trivy is a security scanner

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to i…

▾ Sunlitaquasecurity · github.com/aquasecurity/trivyEPSS 0.19%via NVD
CVE-2026-73502Medium· 5.3
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/…

▾ SunlitRed Hat · Red Hat Edge Manager 1EPSS 0.51%via NVD
CVE-2026-62684Low· 2.7
1mo ago

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.43%via NVD
CVE-2026-50138High· 8.1
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…

▾ Twilightgoshs · goshs.de/goshs/v2EPSS 0.38%via NVD
CVE-2026-50139Medium· 5.9
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…

▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.26%via NVD
GHSA-mpwr-8vm7-h73fMedium
1mo ago

package pkcs12: Authentication bypass in Decode functions

package pkcs12: Authentication bypass in Decode functions

▾ Sunlitsrc · software.sslmate.com/src/go-pkcs12via GHSA
GHSA-fhgh-wq4q-r37xHigh· 7.8
1mo ago

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

▾ Twilightuniget-org · gitlab.com/uniget-org/clivia GHSA
CVE-2026-64859Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.63%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.64%via NVD
CVE-2026-64866Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.47%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.65%via NVD
CVE-2026-64865Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.29%via NVD
CVE-2024-58375High· 7.5⚖ disputed
1mo ago

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive m…

▾ Twilightopentofu · github.com/opentofu/opentofuEPSS 0.43%via NVD
CVE-2026-74796Medium· 6.1
1mo ago

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package content…

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.34%via NVD
CVE-2026-74797Low· 3.1
1mo ago

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling …

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.28%via NVD
CVE-2025-71405Medium
1mo ago

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary ho…

▾ Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.39%via NVD
CVEs tagged “go” — page 13 · VulnSea