VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-53520Medium· 6.5
3mo ago

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.40%via GHSA
CVE-2026-53521Medium· 6.4
3mo ago

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.31%via GHSA
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-53522Medium· 6.5
3mo ago

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.41%via GHSA
CVE-2026-53523Medium· 6.8
3mo ago

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.32%via GHSA
CVE-2026-49340High· 8.1
3mo ago

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.43%via GHSA
CVE-2026-49339High· 7.1
3mo ago

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.39%via GHSA
CVE-2026-49338High· 7.1
3mo ago

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.29%via GHSA
GHSA-ww5p-j6cj-6mqqMedium
3mo ago

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-41568None
3mo ago

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

▾ Sunlitdocker · github.com/docker/dockerEPSS 0.10%via OSV
CVE-2026-40161None
3mo ago

Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline

Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.43%via OSV
CVE-2026-40923None
3mo ago

Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline

Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.32%via OSV
CVE-2026-25542None
3mo ago

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.39%via OSV
CVE-2026-40924None
3mo ago

Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline

Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline

▾ Sunlittektoncd · github.com/tektoncd/pipelineEPSS 0.47%via OSV
CVE-2026-42576None
3mo ago

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.45%via OSV
CVE-2026-42575None
3mo ago

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.23%via OSV
CVE-2026-40179NonePoC
3mo ago

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

▾ Twilightprometheus · github.com/prometheus/prometheusEPSS 0.31%via OSV
GHSA-r4v7-6wcg-ghj5Medium· 6.5
3mo ago

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowservia GHSA
GHSA-rjr7-jggh-pgcpHigh
3mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-9g5q-2w5x-hmxfHigh
3mo ago

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-3fxj-6jh8-hvhxMedium
3mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

▾ Sunlitgo-chi · github.com/go-chi/chi/v5/middlewarevia GHSA
CVE-2026-48529Medium· 6.0
3mo ago

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

▾ Sunlitgithub · github.com/github/github-mcp-serverEPSS 0.21%via GHSA
CVE-2026-48708High· 7.5
3mo ago

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

▾ TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.54%via GHSA
CVE-2026-48709Low· 3.7
3mo ago

OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration

OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.42%via GHSA
CVE-2026-10609Medium· 6.8
3mo ago

OpenShift Cluster Logging Operator missing authorization flaw

OpenShift Cluster Logging Operator missing authorization flaw

▾ Sunlitopenshift · github.com/openshift/cluster-logging-operatorEPSS 0.38%via OSV
GHSA-pvrg-q6jw-42p7High· 7.5
3mo ago

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

▾ Twilighttraefik · github.com/traefik/traefikvia GHSA
CVE-2026-45135High· 8.1
3mo ago

caddy: github.com/caddyserver/caddy/v2: Caddy: Remote Code Execution via Unsafe Unicode Handling in FastCGI (CVE-2026-45135)

A flaw was found in Caddy. This vulnerability stems from unsafe handling of Unicode characters within the FastCGI component, specifically when processing request paths containing non-ASCII bytes. An attacker capable of placing content into…

▾ TwilightRed Hat · github.com/caddyserver/caddy/v2EPSS 0.68%via CSAF
CVE-2023-54365High· 7.5
3mo ago

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…

▾ Twilighttraefik · traefikEPSS 0.77%via NVD
CVE-2026-52800High· 8.8
3mo ago

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

▾ Twilightgogs · gogs.io/gogsEPSS 0.25%via GHSA
CVE-2026-52801High· 8.1
3mo ago

Gogs has the ability to import local repositories via Mirror Settings

Gogs has the ability to import local repositories via Mirror Settings

▾ Twilightgogs · gogs.io/gogsEPSS 0.57%via GHSA
CVEs tagged “go” — page 25 · VulnSea