Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2026-54763HighTraefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
CVE-2026-71324Critical· 9.1Traefik is an open source HTTP reverse proxy and load balancer
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a sh…
CVE-2026-34966High· 7.6Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
CVE-2026-65602MediumTraefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
CVE-2026-65601MediumTraefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
GHSA-gwfq-86j8-7qhvLow· 2.7rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
GHSA-945v-v9p3-v5xwLow· 3.6rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
CVE-2026-71309Highrclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic…
CVE-2026-54572High· 7.5rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
CVE-2026-71310Medium· 5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over…
GHSA-3x6r-wxxg-53vvMedium· 5.3rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-8v25-v8p6-qf7vMedium· 6.5rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8mxv-9xhp-86h4Medium· 5.3rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
CVE-2026-71311Medium· 6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…
GHSA-h4mf-4v27-hggjMedium· 5.3rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
CVE-2026-71312High· 8.0rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…
CVE-2026-59733High· 8.8rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-gx4c-2hqx-cw2rLow· 3.1rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-59732Medium· 5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVE-2026-71313Medium· 6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …
CVE-2026-48154Medium· 5.9GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA …
GHSA-g64v-qqpg-v37hCritical· 8.6Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
CVE-2026-48031Critical· 9.1go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public …
CVE-2026-48113HighChisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The …
CVE-2026-54908MediumPion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
CVE-2026-54910High· 7.7FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
CVE-2026-54787Low· 3.1sigstore-go is a Go library for Sigstore signing and verification
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without…
CVE-2026-54909Medium· 5.3Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
CVE-2026-53551Mediumfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control …
CVE-2026-54725Critical· 9.6vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…