Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
GHSA-r277-6w6q-xmqwCritical· 9.1kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
CVE-2026-44210Critical· 9.9kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)
A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…
GO-2026-6019NoneSkipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
GO-2026-6016Noneoapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen
CVE-2026-46600High· 7.5golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing (CVE-2026-46600)
A flaw was found in golang.org/x/net/dns/dnsmessage. A remote attacker could send a specially crafted Service Binding (SVCB) or HTTPS resource record (RR) to a system using this component. When parsing this invalid record, the system may p…
CVE-2026-59765Medium· 7.5Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore
Gitea: Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-55987High· 8.1Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-58437High· 7.1Gitea: Repository Visibility Manipulation via Git Push Options
Gitea: Repository Visibility Manipulation via Git Push Options
CVE-2026-56657Medium· 6.2Gitea SSH Key Parser Denial of Service
Gitea SSH Key Parser Denial of Service
CVE-2026-58436HighGitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
Gitea: Two SSRF findings
CVE-2026-58419High· 7.5Gitea: Notification API leaks private issue metadata after access revocation
Gitea: Notification API leaks private issue metadata after access revocation
CVE-2026-58422HighGitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58427MediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58431Medium· 4.3Gitea: Public-only API token restriction is not enforced on team API routes
Gitea: Public-only API token restriction is not enforced on team API routes
CVE-2026-58510Medium· 4.3Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-57897Medium· 6.5Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-58511Low· 2.7Gitea: Webhook Authorization Header Returned in Plaintext via API
Gitea: Webhook Authorization Header Returned in Plaintext via API
CVE-2026-58440Medium· 6.8Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
CVE-2026-59766Medium· 4.3Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
CVE-2026-58439High· 8.1Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-58428Medium· 6.5Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-56750CriticalGitea Remember-Me Token Theft Not Invalidating Attacker Session
Gitea Remember-Me Token Theft Not Invalidating Attacker Session