Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-72816Medium· 6.5go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…
CVE-2026-72817Medium· 6.5go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …
CVE-2026-72815Medium· 6.5PoCgo-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access…
CVE-2026-53657High· 8.2Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
CVE-2026-46603High· 7.5golang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation (CVE-2026-46603)
A flaw was found in golang.org/x/image/vp8l. A remote attacker can cause a denial of service by providing a specially crafted VP8L image. This image, containing many unused Huffman tree groups, leads to excessive memory allocation during V…
CVE-2026-35511HighAuthorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
CVE-2026-49826LowConcourse is a container-based automation system written in Go
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…
CVE-2026-19730Medium· 4.2PoCThe 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL defau…
CVE-2026-73842Critical· 9.0OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requir…
CVE-2026-73843Critical· 9.6OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication,…
CVE-2026-73841High· 8.8OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…
CVE-2026-73840Medium· 5.3OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…
CVE-2026-73667High· 8.8OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workf…
CVE-2026-56860High· 7.5Avoid quadratic complexity in resolvePath in net/url
Avoid quadratic complexity in resolvePath in net/url
CVE-2026-56864High· 8.1golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB (CVE-2026-56864)
A flaw was found in golang.org/x/mod/sumdb. A malicious Go checksum database (GOSUMDB) can serve arbitrary module content that is not recorded in the transparency log. This allows a coordinated Go proxy (GOPROXY) and GOSUMDB to deliver mal…
CVE-2026-56865High· 8.8golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…
A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…
CVE-2026-56858High· 8.1Fix Javascript regexp context tracking in html/template
Fix Javascript regexp context tracking in html/template
CVE-2026-56862High· 7.5Limit handshake messages we are willing to accept post-handshake in crypto/tls
Limit handshake messages we are willing to accept post-handshake in crypto/tls
CVE-2026-56853High· 7.5net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
A flaw was found in the `net/http` component of the Go standard library. When a server is configured to support unencrypted HTTP/2, it reads initial bytes from new connections to detect the HTTP/2 client preface. However, the `ReadHeaderTi…
CVE-2026-56859High· 7.5Add recursion depth guard during decode in encoding/xml
Add recursion depth guard during decode in encoding/xml
CVE-2026-33818High· 7.5Enforce maximum recursion depth in encoding/asn1
Enforce maximum recursion depth in encoding/asn1
CVE-2026-73506Medium· 6.1Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…
CVE-2026-73509High· 7.6OpenList a file list program that supports multiple storage
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and valid…
CVE-2026-73505High· 7.8Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…
CVE-2026-73564Highfrp is a fast reverse proxy
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF ma…
CVE-2026-54526HighArgo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
CVE-2026-58443Critical· 9.6code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)
A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…
CVE-2026-49820Medium· 4.7Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAu…
CVE-2026-49478High· 8.7⚖ disputedFulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…
CVE-2026-48702High· 7.5Rekor is a software supply chain transparency log
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…