VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

GHSA-r277-6w6q-xmqwCritical· 9.1
2mo ago

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

▾ Midnightgetkin · github.com/getkin/kin-openapivia GHSA
CVE-2026-44210Critical· 9.9
2mo ago

kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.59%via CSAF
GO-2026-6019None
2mo ago

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

▾ Sunlitzalando · github.com/zalando/skippervia OSV
GO-2026-6016None
2mo ago

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen

▾ Sunlitoapi-codegen · github.com/oapi-codegen/oapi-codegenvia OSV
CVE-2026-46600High· 7.5
2mo ago

golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing (CVE-2026-46600)

A flaw was found in golang.org/x/net/dns/dnsmessage. A remote attacker could send a specially crafted Service Binding (SVCB) or HTTPS resource record (RR) to a system using this component. When parsing this invalid record, the system may p…

▾ TwilightRed Hat · Multicluster Engine for KubernetesEPSS 0.63%via CSAF
CVE-2026-59765Medium· 7.5
2mo ago

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.50%via GHSA
CVE-2026-58429Medium· 4.9
2mo ago

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

▾ Twilightgrpc · google.golang.org/grpcvia GHSA
CVE-2026-55984Low· 2.7
2mo ago

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-58420Medium
2mo ago

Gitea: Local File Inclusion via file:// URI in Migration Restore

Gitea: Local File Inclusion via file:// URI in Migration Restore

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58435Medium· 5.4
2mo ago

Gitea LFS Deploy-Key Privilege Escalation

Gitea LFS Deploy-Key Privilege Escalation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-55987High· 8.1
2mo ago

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58437High· 7.1
2mo ago

Gitea: Repository Visibility Manipulation via Git Push Options

Gitea: Repository Visibility Manipulation via Git Push Options

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-56657Medium· 6.2
2mo ago

Gitea SSH Key Parser Denial of Service

Gitea SSH Key Parser Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via OSV
CVE-2026-58436High
2mo ago

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.61%via GHSA
CVE-2026-58314High· 7.7
2mo ago

Gitea: Two SSRF findings

Gitea: Two SSRF findings

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.40%via OSV
CVE-2026-58419High· 7.5
2mo ago

Gitea: Notification API leaks private issue metadata after access revocation

Gitea: Notification API leaks private issue metadata after access revocation

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-58422High
2mo ago

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.62%via GHSA
CVE-2026-58427Medium
2mo ago

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58431Medium· 4.3
2mo ago

Gitea: Public-only API token restriction is not enforced on team API routes

Gitea: Public-only API token restriction is not enforced on team API routes

▾ Sunlitgitea.dev · gitea.devEPSS 0.33%via GHSA
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-57897Medium· 6.5
2mo ago

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58511Low· 2.7
2mo ago

Gitea: Webhook Authorization Header Returned in Plaintext via API

Gitea: Webhook Authorization Header Returned in Plaintext via API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.39%via GHSA
CVE-2026-58440Medium· 6.8
2mo ago

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

▾ Sunlitgitea.dev · gitea.devEPSS 0.48%via GHSA
CVE-2026-59766Medium· 4.3
2mo ago

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58439High· 8.1
2mo ago

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-56443Medium· 4.3
2mo ago

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via OSV
CVE-2026-58428Medium· 6.5
2mo ago

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-56750Critical
2mo ago

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.48%via GHSA
CVEs tagged “go” — page 19 · VulnSea