VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.30%via NVD
CVE-2026-72817Medium· 6.5
1mo ago

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.24%via NVD
CVE-2026-72815Medium· 6.5PoC
1mo ago

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access…

▾ Twilightgo-chi · github.com/go-chi/chi/v5/middlewareEPSS 0.50%via NVD
CVE-2026-53657High· 8.2
1mo ago

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

▾ Twilightlima-vm · github.com/lima-vm/lima/v2EPSS 0.20%via GHSA
CVE-2026-46603High· 7.5
1mo ago

golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation (CVE-2026-46603)

A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during V…

▾ TwilightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.16EPSS 0.75%via CSAF
CVE-2026-35511High
1mo ago

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

▾ Twilightauthorizerdev · github.com/authorizerdev/authorizervia GHSA
CVE-2026-49826Low
1mo ago

Concourse is a container-based automation system written in Go

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…

▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.53%via NVD
CVE-2026-19730Medium· 4.2PoC
1mo ago

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL defau…

▾ TwilightRed Hat · podmanEPSS 0.16%via NVD
CVE-2026-73842Critical· 9.0
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requir…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.27%via NVD
CVE-2026-73843Critical· 9.6
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication,…

▾ Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.48%via NVD
CVE-2026-73841High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.81%via NVD
CVE-2026-73840Medium· 5.3
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…

▾ Sunlitopenchoreo · github.com/openchoreo/openchoreoEPSS 0.35%via NVD
CVE-2026-73667High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workf…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.86%via NVD
CVE-2026-56860High· 7.5
1mo ago

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

▾ Twilightstdlib · stdlibEPSS 0.55%via OSV
CVE-2026-56864High· 8.1
1mo ago

golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)

A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.32%via CSAF
CVE-2026-56865High· 8.8
1mo ago

golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…

A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.14%via CSAF
CVE-2026-56858High· 8.1
1mo ago

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

▾ Twilightstdlib · stdlibEPSS 0.31%via OSV
CVE-2026-56862High· 7.5
1mo ago

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-56853High· 7.5
1mo ago

net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)

A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTi…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.57%via CSAF
CVE-2026-56859High· 7.5
1mo ago

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-33818High· 7.5
1mo ago

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-73506Medium· 6.1
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…

▾ Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.18%via NVD
CVE-2026-73509High· 7.6
1mo ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and valid…

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4EPSS 0.52%via NVD
CVE-2026-73505High· 7.8
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.21%via NVD
CVE-2026-73564High
1mo ago

frp is a fast reverse proxy

frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF ma…

▾ Twilightfatedier · github.com/fatedier/frpEPSS 0.52%via NVD
CVE-2026-54526High
1mo ago

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.55%via GHSA
CVE-2026-58443Critical· 9.6
1mo ago

code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…

▾ MidnightRed Hat · OpenShift PipelinesEPSS 0.58%via CSAF
CVE-2026-49820Medium· 4.7
1mo ago

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAu…

▾ Sunlitprobo · go.probo.inc/proboEPSS 0.42%via NVD
CVE-2026-49478High· 8.7⚖ disputed
1mo ago

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.28%via NVD
CVE-2026-48702High· 7.5
1mo ago

Rekor is a software supply chain transparency log

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
CVEs tagged “go” — page 14 · VulnSea