Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-55667High· 8.2File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55668Medium· 6.3File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
GO-2026-5985NoneNebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
GO-2026-5982NoneTsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
GO-2026-5981NoneEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com…
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0
GO-2026-5969NoneTSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
GO-2026-5935Nonenetfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil
GO-2026-5934Nonenetfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil
netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil
GO-2026-5933Nonenetfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil
netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil
GHSA-8qqm-fp2q-v734High· 8.2Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
GHSA-rjwr-m7qx-3fjrLowoapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
CVE-2026-50274High· 7.5github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)
A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…
CVE-2026-49834Medium· 5.9github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)
A flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An at…
CVE-2026-18679Mediumkuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-18678Mediumkumactl connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-56742Medium· 5.9Cilium is a networking, observability, and security solution
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any S…
CVE-2026-56852High· 7.5PoCInfinite loop on invalid input in golang.org/x/text
Infinite loop on invalid input in golang.org/x/text
GHSA-pqg7-v6wh-3pfpHigh· 8.5TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
CVE-2026-54448HighTrivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
GHSA-mqxv-9rm6-w8qcHighEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
GHSA-7rx3-5wx3-5v76High· 7.7Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
CVE-2026-50141HighWoodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-54250Medium· 5.8K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…
CVE-2026-59162High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…
CVE-2026-59161High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
CVE-2026-50551Critical· 9.9SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
CVE-2026-54067Critical· 9.9SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()