Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-54063High· 7.5Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
CVE-2026-54068Medium· 5.9SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
CVE-2026-54069CriticalPoCSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-54070High· 7.1SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
CVE-2026-54088CriticalPoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
CVE-2026-54158Critical· 9.9SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVE-2026-55252MediumOpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
CVE-2026-55874High· 7.7SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)
A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…
CVE-2026-42505Medium· 5.3Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
CVE-2026-39822High· 7.8On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will o…
CVE-2026-50197High· 8.7Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
GO-2026-5932NoneThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GO-2026-5923NoneCoder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
GO-2026-5410NoneSecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack
SecretsVerifier accepts empty signing secret without precondition in github.com/slack-go/slack
GHSA-59qp-cfj3-rp64Mediumnetfoil has a domain name filter bypass via multiple questions
netfoil has a domain name filter bypass via multiple questions
GHSA-3g4q-2f67-2gvhLownetfoil has a resource leak in LRU cache
netfoil has a resource leak in LRU cache
GHSA-7856-g3gv-9wq8Lownetfoil: Attacker controlled data written to logs
netfoil: Attacker controlled data written to logs
CVE-2026-33655High· 7.7New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-44342Medium· 5.3New API is vulnerable to CSRF through user email binding
New API is vulnerable to CSRF through user email binding
GHSA-qrwj-vh9x-gw5vHigh· 8.3Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CVE-2026-55076High· 7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVE-2026-55075High· 7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVE-2026-55077High· 7.2Coder: User-admin role can reset owner account password
Coder: User-admin role can reset owner account password
CVE-2026-55427High· 8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVE-2026-55079Medium· 4.9Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
CVE-2026-55429High· 8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVE-2026-55428High· 8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE-2026-55430Medium· 5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access