VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

GHSA-6c87-g9pw-78fxLow· 3.7
2mo ago

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
GHSA-3ccm-4qq2-5wrpMedium· 4.3
2mo ago

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
CVE-2026-53488High· 8.8
2mo ago

github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.16%via CSAF
CVE-2026-53489Medium· 6.5
2mo ago

github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.17%via CSAF
CVE-2026-53492High· 8.2
2mo ago

github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.35%via CSAF
GHSA-55f6-4pr5-c7m5High
2mo ago

Kahi has privilege-drop and socket/log permission issues

Kahi has privilege-drop and socket/log permission issues

▾ Twilightkahiteam · github.com/kahiteam/kahivia GHSA
GHSA-7m8x-qg2j-4m3vHigh· 8.1
2mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

▾ Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-49821High· 7.7
2mo ago

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49822High· 7.7
2mo ago

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49823High· 7.7
2mo ago

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-49824High· 8.5
2mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-50545Critical· 9.9
2mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-50563Critical· 9.9
2mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50564Critical· 9.9
2mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50565Medium· 4.9
2mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

▾ Sunlitfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-50566Critical· 9.9
2mo ago

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-49835Medium· 5.9
2mo ago

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

▾ Sunlitsigstore · github.com/sigstore/timestamp-authority/v2EPSS 0.74%via GHSA
CVE-2026-11720Critical· 9.1
3mo ago

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

▾ Midnightgoogleapis · github.com/googleapis/mcp-toolboxEPSS 0.53%via OSV
CVE-2026-44840High· 7.5PoC
3mo ago

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.49%via GHSA
CVE-2026-55677High· 7.5
3mo ago

github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)

A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.9.2)EPSS 0.43%via CSAF
CVE-2026-48788High· 8.2
3mo ago

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing

▾ Twilightumputun · github.com/umputun/remark42EPSS 0.41%via GHSA
GHSA-vgrc-hq28-p3xpHigh· 7.4
3mo ago

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

▾ Twilightapernet · github.com/apernet/hysteria/core/v2via GHSA
GHSA-qh5x-rfwf-rvfvHigh· 7.5
3mo ago

Hysteria vulnerable to server crash when max_datagram_frame_size very small

Hysteria vulnerable to server crash when max_datagram_frame_size very small

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
GHSA-jqc5-2p7q-fqfcHigh· 7.5
3mo ago

Hysteria: http large header with sniff cause server DoS

Hysteria: http large header with sniff cause server DoS

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
GHSA-rhq6-9rgh-v45cMedium· 5.0
3mo ago

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

▾ Sunlitpterodactyl · github.com/pterodactyl/wingsvia GHSA
GHSA-v2jf-442r-6mjhLow
3mo ago

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2026-49258High· 8.8
3mo ago

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
GHSA-wcr3-9x4c-f5gjHigh
3mo ago

Blnk has an API key authorization bypass in owner and scope enforcement

Blnk has an API key authorization bypass in owner and scope enforcement

▾ Twilightblnkfinance · github.com/blnkfinance/blnkvia GHSA
GHSA-q6xx-5vr8-p898Critical· 9.9
3mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

▾ Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-48794Low
3mo ago

Authelia has an Edge Case Access Control Rule Mismatch

Authelia has an Edge Case Access Control Rule Mismatch

▾ Sunlitauthelia · github.com/authelia/authelia/v4EPSS 0.41%via GHSA
CVEs tagged “go” — page 24 · VulnSea