Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
CVE-2026-53521Medium· 6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-53522Medium· 6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVE-2026-53523Medium· 6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
GHSA-ww5p-j6cj-6mqqMediumNezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
CVE-2026-41568NoneRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
CVE-2026-40161NoneTekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
Tekton Pipelines git resolver leaks API token to user-controlled serverURL in github.com/tektoncd/pipeline
CVE-2026-40923NoneTekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
Tekton Pipelines VolumeMount path restriction bypass via missing filepath.Clean in github.com/tektoncd/pipeline
CVE-2026-25542NoneTekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching in github.com/tektoncd/pipeline
CVE-2026-40924NoneTekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
Tekton Pipelines HTTP resolver denial of service via memory exhaustion in github.com/tektoncd/pipeline
CVE-2026-42576Noneapko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery in chainguard.dev/apko
CVE-2026-42575Noneapko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) in chainguard.dev/apko
CVE-2026-40179NonePoCPrometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
GHSA-r4v7-6wcg-ghj5Medium· 6.5FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
GHSA-rjr7-jggh-pgcpHighchi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
GHSA-9g5q-2w5x-hmxfHighchi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
GHSA-3fxj-6jh8-hvhxMediumchi Has an IP Spoofing Vulnerability in `middleware.RealIP`
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
CVE-2026-48529Medium· 6.0GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
CVE-2026-48708High· 7.5OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
CVE-2026-48709Low· 3.7OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration
OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration
CVE-2026-10609Medium· 6.8OpenShift Cluster Logging Operator missing authorization flaw
OpenShift Cluster Logging Operator missing authorization flaw
GHSA-pvrg-q6jw-42p7High· 7.5Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service
Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service
CVE-2026-45135High· 8.1caddy: github.com/caddyserver/caddy/v2: Caddy: Remote Code Execution via Unsafe Unicode Handling in FastCGI (CVE-2026-45135)
A flaw was found in Caddy. This vulnerability stems from unsafe handling of Unicode characters within the FastCGI component, specifically when processing request paths containing non-ASCII bytes. An attacker capable of placing content into…
CVE-2023-54365High· 7.5Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…
CVE-2026-52800High· 8.8Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-52801High· 8.1Gogs has the ability to import local repositories via Mirror Settings
Gogs has the ability to import local repositories via Mirror Settings