VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-55667High· 8.2
2mo ago

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.49%via GHSA
CVE-2026-55668Medium· 6.3
2mo ago

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.38%via GHSA
GO-2026-5985None
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

▾ Sunlitforgekeep · github.com/forgekeep/nebula-meshvia OSV
GO-2026-5982None
2mo ago

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy

▾ Sunlitalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia OSV
GO-2026-5981None
2mo ago

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com…

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0

▾ Sunlitlin-snow · github.com/lin-snow/ech0via OSV
GO-2026-5969None
2mo ago

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy

▾ Sunlitalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia OSV
GO-2026-5935None
2mo ago

netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil

netfoil: Attacker controlled data written to logs in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GO-2026-5934None
2mo ago

netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil

netfoil has a domain name filter bypass via multiple questions in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GO-2026-5933None
2mo ago

netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil

netfoil has a resource leak in LRU cache in github.com/tinfoil-factory/netfoil

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia OSV
GHSA-8qqm-fp2q-v734High· 8.2
2mo ago

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

▾ Twilightzalando · github.com/zalando/skippervia GHSA
GHSA-rjwr-m7qx-3fjrLow
2mo ago

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

▾ Sunlitoapi-codegen · github.com/oapi-codegen/oapi-codegen/v2via GHSA
CVE-2026-50274High· 7.5
2mo ago

github.com/DataDog/dd-trace-go: Datadog dd-trace-go: Denial of Service via malicious baggage headers (CVE-2026-50274)

A flaw was found in Datadog dd-trace-go, a Go client library. A remote, unauthenticated attacker can exploit this vulnerability by sending a request with a specially crafted baggage header containing an arbitrarily large number of key-valu…

▾ TwilightRed Hat · github.com/DataDog/dd-trace-goEPSS 0.79%via CSAF
CVE-2026-49834Medium· 5.9
2mo ago

github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)

A flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An at…

▾ SunlitRed Hat · Red Hat Trusted Artifact SignerEPSS 0.18%via CSAF
CVE-2026-18679Medium
2mo ago

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

▾ Sunlitkumahq · github.com/kumahq/kuma/v2EPSS 0.16%via OSV
CVE-2026-18678Medium
2mo ago

kumactl connects to control plane without verifying TLS certificate when no CA is configured

kumactl connects to control plane without verifying TLS certificate when no CA is configured

▾ Sunlitkumahq · github.com/kumahq/kuma/v2EPSS 0.13%via OSV
CVE-2026-56742Medium· 5.9
2mo ago

Cilium is a networking, observability, and security solution

Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any S…

▾ Sunlitcilium · ciliumEPSS 0.17%via NVD
CVE-2026-56852High· 7.5PoC
2mo ago

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

▾ Midnightx · golang.org/x/textEPSS 0.47%via OSV
GHSA-pqg7-v6wh-3pfpHigh· 8.5
2mo ago

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

▾ Twilightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-54448High
2mo ago

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
GHSA-mqxv-9rm6-w8qcHigh
2mo ago

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

▾ Twilightlin-snow · github.com/lin-snow/ech0via GHSA
GHSA-7rx3-5wx3-5v76High· 7.7
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

▾ Twilightforgekeep · github.com/forgekeep/nebula-meshvia GHSA
CVE-2026-50141High
2mo ago

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v3EPSS 0.43%via GHSA
CVE-2026-54250Medium· 5.8
2mo ago

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.17%via GHSA
CVE-2026-56666Medium· 4.8
2mo ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…

▾ Sunlitzitadel · zitadelEPSS 0.29%via NVD
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-59161High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
GHSA-g936-7jqj-mwv8Critical· 9.0
2mo ago

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

▾ Midnightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-50551Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.78%via GHSA
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVEs tagged “go” — page 21 · VulnSea