Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
GHSA-6c87-g9pw-78fxLow· 3.7Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
GHSA-3ccm-4qq2-5wrpMedium· 4.3Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
CVE-2026-53488High· 8.8github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…
CVE-2026-53489Medium· 6.5github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…
CVE-2026-53492High· 8.2github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…
GHSA-55f6-4pr5-c7m5HighKahi has privilege-drop and socket/log permission issues
Kahi has privilege-drop and socket/log permission issues
GHSA-7m8x-qg2j-4m3vHigh· 8.1Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
CVE-2026-49821High· 7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
CVE-2026-49822High· 7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVE-2026-49823High· 7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
CVE-2026-49824High· 8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
CVE-2026-50545Critical· 9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50563Critical· 9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-50564Critical· 9.9Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVE-2026-50565Medium· 4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVE-2026-50566Critical· 9.9Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
CVE-2026-49835Medium· 5.9Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
CVE-2026-11720Critical· 9.1MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
CVE-2026-44840High· 7.5PoCDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-55677High· 7.5github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)
A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…
CVE-2026-48788High· 8.2Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
GHSA-vgrc-hq28-p3xpHigh· 7.4Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
GHSA-qh5x-rfwf-rvfvHigh· 7.5Hysteria vulnerable to server crash when max_datagram_frame_size very small
Hysteria vulnerable to server crash when max_datagram_frame_size very small
GHSA-jqc5-2p7q-fqfcHigh· 7.5Hysteria: http large header with sniff cause server DoS
Hysteria: http large header with sniff cause server DoS
GHSA-rhq6-9rgh-v45cMedium· 5.0Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
GHSA-v2jf-442r-6mjhLownebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
CVE-2026-49258High· 8.8Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
GHSA-wcr3-9x4c-f5gjHighBlnk has an API key authorization bypass in owner and scope enforcement
Blnk has an API key authorization bypass in owner and scope enforcement
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-48794LowAuthelia has an Edge Case Access Control Rule Mismatch
Authelia has an Edge Case Access Control Rule Mismatch