Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-54345MediumGoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
CVE-2026-54332MediumGoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
CVE-2026-43983HighPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
GHSA-hp74-gm6m-2qm5MediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
CVE-2026-47427High· 7.5GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
GO-2026-6061NoneVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
GO-2026-5841NoneOOB read in github.com/klauspost/compress/s2
OOB read in github.com/klauspost/compress/s2
GO-2026-5781NoneUncatchable stack-overflow denial of service in rsc.io/pdf
Uncatchable stack-overflow denial of service in rsc.io/pdf
GO-2026-5051NoneOut-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2
Out-of-bounds read and panic in ReadDir in github.com/cloudsoda/go-smb2 and github.com/hirochachacha/go-smb2
GO-2026-5048NoneDenial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
GO-2026-5884NoneORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
GO-2026-5777NoneChi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
GO-2026-5775NoneChi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
GO-2026-5774NoneChi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
GO-2026-5730NoneCaddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
GO-2026-5693NoneGo-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
GO-2026-5408NoneCaddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
GHSA-jpcw-4wr7-c3vqMedium· 5.3kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-c534-2w9c-x7fmMedium· 6.5Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-26gq-p25f-99cpHighfrp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-95cv-r8x4-vh75High· 7.6OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-p6ph-3jx2-3337Medium· 4.3OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-86cx-wwf4-phq4Medium· 6.5OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-fwjx-9p69-h25hMedium· 6.1Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-xg4h-6gfc-h4m8Highetcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
GHSA-gcjh-h69q-9w9gMediumcel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag