VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.24%via GHSA
CVE-2026-71324Critical· 9.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a sh…

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-34966High· 7.6
1mo ago

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.39%via NVD
CVE-2026-65602Medium
1mo ago

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.33%via GHSA
CVE-2026-65601Medium
1mo ago

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

▾ SunlitTraefik · TraefikEPSS 0.51%via GHSA
GHSA-gwfq-86j8-7qhvLow· 2.7
1mo ago

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-945v-v9p3-v5xwLow· 3.6
1mo ago

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-71309High
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic…

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.46%via NVD
CVE-2026-54572High· 7.5
1mo ago

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.40%via GHSA
CVE-2026-71310Medium· 5.9
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.61%via NVD
GHSA-3x6r-wxxg-53vvMedium· 5.3
1mo ago

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-8v25-v8p6-qf7vMedium· 6.5
1mo ago

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
GHSA-8mxv-9xhp-86h4Medium· 5.3
1mo ago

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-71311Medium· 6.4
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.39%via NVD
GHSA-h4mf-4v27-hggjMedium· 5.3
1mo ago

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-71312High· 8.0
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.49%via NVD
CVE-2026-59733High· 8.8
1mo ago

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.55%via GHSA
GHSA-gx4c-2hqx-cw2rLow· 3.1
1mo ago

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-59732Medium· 5.0
1mo ago

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.20%via OSV
CVE-2026-71313Medium· 6.9
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.37%via NVD
CVE-2026-48154Medium· 5.9
1mo ago

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA …

▾ Sunlitpilinux · github.com/pilinux/gorestEPSS 0.40%via NVD
GHSA-g64v-qqpg-v37hCritical· 8.6
1mo ago

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

Duplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-48031Critical· 9.1
1mo ago

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public …

▾ Midnightdhax · github.com/dhax/go-baseEPSS 0.63%via NVD
CVE-2026-48113High
1mo ago

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The …

▾ Twilightjpillora · github.com/jpillora/chiselEPSS 0.39%via NVD
CVE-2026-54908Medium
1mo ago

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

▾ Sunlitpion · github.com/pion/dtls/v3EPSS 0.54%via GHSA
CVE-2026-54910High· 7.7
1mo ago

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

▾ Twilightgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.46%via GHSA
CVE-2026-54787Low· 3.1
1mo ago

sigstore-go is a Go library for Sigstore signing and verification

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without…

▾ Sunlitsigstore · github.com/sigstore/sigstore-goEPSS 0.13%via NVD
CVE-2026-54909Medium· 5.3
1mo ago

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

▾ Sunlitpion · github.com/pion/stun/v3EPSS 0.64%via OSV
CVE-2026-53551Medium
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control …

▾ Sunlitfree5gc · github.com/free5gc/free5gcEPSS 0.74%via NVD
CVE-2026-54725Critical· 9.6
1mo ago

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…

▾ Midnightbank-vaults · github.com/bank-vaults/vault-secrets-webhookEPSS 0.45%via NVD
CVEs tagged “go” — page 16 · VulnSea