Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-55078Medium· 6.5Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
CVE-2026-55431High· 7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVE-2026-55432Medium· 5.4Coder's sub-agent app registration bypasses template port-sharing policy enforcement
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
CVE-2026-55433Medium· 5.4Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
CVE-2026-55434Medium· 6.5Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
CVE-2026-55435Medium· 5.4Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE-2026-55436High· 7.4Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-55437Medium· 5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
CVE-2026-55438Medium· 5.8Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
CVE-2026-53624Medium· 4.8GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
CVE-2026-53935Medium· 6.9CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
CVE-2026-46599High· 7.5golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
CVE-2026-44454High· 8.1Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
CVE-2026-44332Medium· 5.3GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-45045Medium· 5.3GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
CVE-2026-50151Medium· 5.9oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)
A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…
CVE-2026-50162Medium· 5.3oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
CVE-2026-49998High· 8.2Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
CVE-2026-44938High· 8.8Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-44937High· 7.5Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
CVE-2026-44939Critical· 9.6Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-44936Medium· 5.0Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
CVE-2026-44935Critical· 9.9Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVE-2026-41053High· 8.8Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
CVE-2026-48824Medium· 5.3Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
CVE-2026-41052Critical· 8.4Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens