VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-55078Medium· 6.5
2mo ago

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.60%via GHSA
CVE-2026-55431High· 7.7
2mo ago

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.34%via GHSA
CVE-2026-55432Medium· 5.4
2mo ago

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55433Medium· 5.4
2mo ago

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.39%via GHSA
CVE-2026-55434Medium· 6.5
2mo ago

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.55%via GHSA
CVE-2026-55435Medium· 5.4
2mo ago

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55436High· 7.4
2mo ago

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.26%via GHSA
CVE-2026-55437Medium· 5.4
2mo ago

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55438Medium· 5.8
2mo ago

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.22%via GHSA
CVE-2026-53624Medium· 4.8
2mo ago

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

▾ Sunlitgofiber · github.com/gofiber/fiberEPSS 0.21%via GHSA
CVE-2026-53935Medium· 6.9
2mo ago

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.34%via GHSA
CVE-2026-49445Critical· 9.2
2mo ago

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

▾ Midnightcilium · github.com/cilium/ciliumEPSS 0.17%via GHSA
CVE-2026-46599High· 7.5
2mo ago

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

▾ Twilightx · golang.org/x/imageEPSS 0.63%via GHSA
CVE-2026-44454High· 8.1
2mo ago

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

▾ Twilightcoder · github.com/coder/coder/v2EPSS 2.6%via GHSA
CVE-2026-44332Medium· 5.3
2mo ago

GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer

GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.52%via GHSA
CVE-2026-45045Medium· 5.3
2mo ago

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.46%via GHSA
CVE-2026-50151Medium· 5.9
2mo ago

oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-50162Medium· 5.3
2mo ago

oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)

A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…

▾ SunlitRed Hat · Red Hat Edge Manager 1.1EPSS 0.51%via CSAF
CVE-2026-50163High· 7.1
2mo ago

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

▾ Twilightoras-go · oras.land/oras-go/v2EPSS 0.43%via GHSA
GHSA-vh4v-2xq2-g5cgMedium
2mo ago

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

▾ Sunlitoras-go · oras.land/oras-go/v2via GHSA
CVE-2026-49998High· 8.2
2mo ago

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

▾ Twilightcentrifugal · github.com/centrifugal/centrifugo/v6EPSS 0.27%via GHSA
CVE-2026-44938High· 8.8
2mo ago

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

▾ Twilightrancher · github.com/rancher/fleetEPSS 0.44%via GHSA
CVE-2026-44937High· 7.5
2mo ago

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

▾ Twilightrancher · github.com/rancher/fleetEPSS 0.42%via GHSA
CVE-2026-44939Critical· 9.6
2mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

▾ Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-44936Medium· 5.0
2mo ago

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

▾ Sunlitrancher · github.com/rancher/fleetEPSS 0.35%via GHSA
CVE-2026-44935Critical· 9.9
2mo ago

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

▾ Midnightrancher · github.com/rancher/fleetEPSS 0.49%via GHSA
CVE-2026-41053High· 8.8
2mo ago

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.52%via OSV
CVE-2026-48824Medium· 5.3
2mo ago

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.54%via GHSA
CVE-2026-41052Critical· 8.4
2mo ago

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.42%via GHSA
CVE-2026-48978Low
2mo ago

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

▾ Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA
CVEs tagged “go” — page 23 · VulnSea