VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-54345Medium
2mo ago

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via OSV
CVE-2026-54332Medium
2mo ago

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via GHSA
CVE-2026-43983High
2mo ago

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

▾ Twilightpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.36%via GHSA
GHSA-hp74-gm6m-2qm5Medium
2mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia GHSA
CVE-2026-47427High· 7.5
2mo ago

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

▾ Twilightgithub · github.com/github/github-mcp-serverEPSS 0.77%via GHSA
GO-2026-6074None
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

▾ Sunlitgitea · code.gitea.io/giteavia OSV
GO-2026-6061None
2mo ago

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

▾ Sunlitgrpc · google.golang.org/grpcvia OSV
GO-2026-5841None
2mo ago

OOB read in github.com/klauspost/compress/s2

OOB read in github.com/klauspost/compress/s2

▾ Sunlitklauspost · github.com/klauspost/compressvia OSV
GO-2026-5781None
2mo ago

Uncatchable stack-overflow denial of service in rsc.io/pdf

Uncatchable stack-overflow denial of service in rsc.io/pdf

▾ Sunlitpdf · rsc.io/pdfvia OSV
GO-2026-5051None
2mo ago

Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2

Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2

▾ Sunlitcloudsoda · github.com/cloudsoda/go-smb2via OSV
GO-2026-5048None
2mo ago

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

▾ Sunlitiskorotkov · github.com/iskorotkov/avro/v2via OSV
GO-2026-5884None
2mo ago

ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go

ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go

▾ Sunlitoras-go · oras.land/oras-go/v2via OSV
GO-2026-5777None
2mo ago

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5775None
2mo ago

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5774None
2mo ago

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

▾ Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5730None
2mo ago

Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy

Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
GO-2026-5693None
2mo ago

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

▾ Sunlitgo-git · github.com/go-git/go-git/v5via OSV
GO-2026-5408None
2mo ago

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2via OSV
GHSA-jpcw-4wr7-c3vqMedium· 5.3
2mo ago

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

▾ Sunlitgetkin · github.com/getkin/kin-openapivia GHSA
GHSA-6vch-q96h-7gc3High
2mo ago

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-c534-2w9c-x7fmMedium· 6.5
2mo ago

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

▾ Sunlitzxh326 · github.com/zxh326/kitevia GHSA
GHSA-26gq-p25f-99cpHigh
2mo ago

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

▾ Twilightfatedier · github.com/fatedier/frpvia GHSA
GHSA-v6w6-358x-2433Medium· 5.4
2mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-95cv-r8x4-vh75High· 7.6
2mo ago

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-p6ph-3jx2-3337Medium· 4.3
2mo ago

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-86cx-wwf4-phq4Medium· 6.5
2mo ago

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-fwjx-9p69-h25hMedium· 6.1
2mo ago

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

▾ Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
GHSA-6xj8-qv9j-xcjqHigh· 7.8
2mo ago

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
GHSA-xg4h-6gfc-h4m8High
2mo ago

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-gcjh-h69q-9w9gMedium
2mo ago

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

▾ Sunlitgoogle · github.com/google/cel-govia GHSA
CVEs tagged “go” — page 18 · VulnSea