VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-41579Medium· 3.3
3mo ago

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 0.17%via GHSA
CVE-2026-47267Medium
3mo ago

Gogs has SSRF in webhook deliveries

Gogs has SSRF in webhook deliveries

▾ Sunlitgogs · gogs.io/gogsEPSS 0.42%via GHSA
GHSA-ghmh-jhmj-wcmfMedium
3mo ago

nebula-mesh's stores enrollment tokens unhashed in SQLite

nebula-mesh's stores enrollment tokens unhashed in SQLite

▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2026-52796Low· 3.5
3mo ago

Gogs has DoS in rendering issue index pattern

Gogs has DoS in rendering issue index pattern

▾ Sunlitgogs · gogs.io/gogsEPSS 0.28%via GHSA
CVE-2026-52798High· 8.9
3mo ago

Gogs has Stored XSS in `.ipynb` Preview

Gogs has Stored XSS in `.ipynb` Preview

▾ Twilightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2026-52799High· 7.5
3mo ago

Gogs Missing Authorization in Attachment Download

Gogs Missing Authorization in Attachment Download

▾ Twilightgogs · gogs.io/gogsEPSS 0.42%via GHSA
GHSA-24r3-p3x6-cqvxCritical· 9.6
3mo ago

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-56395Medium
3mo ago

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via NVD
CVE-2026-27878Medium· 6.5
3mo ago

Grafana Tempo vulnerable to an out-of-memory crash

Grafana Tempo vulnerable to an out-of-memory crash

▾ Sunlitgrafana · github.com/grafana/tempoEPSS 0.41%via OSV
CVE-2026-58404High
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

▾ Twilightgohugoio · github.com/gohugoio/hugoEPSS 0.37%via OSV
CVE-2026-58402Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.30%via OSV
CVE-2026-58403Medium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.47%via OSV
CVE-2026-10720Medium
3mo ago

Canonical MicroCeph: path traversal issue in the remote-import AP

Canonical MicroCeph: path traversal issue in the remote-import AP

▾ Sunlitcanonical · github.com/canonical/microceph/microcephEPSS 0.30%via GHSA
CVE-2026-55882High
3mo ago

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.52%via GHSA
CVE-2026-55883High
3mo ago

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.26%via GHSA
CVE-2026-55884Critical
3mo ago

Tilt: Missing authentication on the network-exposed Tilt HUD server

Tilt: Missing authentication on the network-exposed Tilt HUD server

▾ Midnighttilt-dev · github.com/tilt-dev/tiltEPSS 0.50%via GHSA
CVE-2026-55689Medium· 6.8
3mo ago

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.41%via GHSA
GHSA-2h46-9x5w-4wf7Medium
3mo ago

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

▾ Sunlitentireio · github.com/entireio/clivia GHSA
GHSA-q7j3-v8qv-22vqHigh· 7.5
3mo ago

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

▾ Twilightopentofu · github.com/opentofu/opentofuvia GHSA
GHSA-q76j-gcg9-vxc6Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-c3wq-j5vh-68rcMedium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-r46f-3rpw-hxrvHigh
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

▾ Twilightgohugoio · github.com/gohugoio/hugovia GHSA
CVE-2026-47262Medium
3mo ago

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.26%via GHSA
CVE-2026-50195Medium
3mo ago

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.30%via GHSA
GHSA-x845-2f78-7v36High· 8.6
3mo ago

Blocky DNSSEC validation bypass and validation-cache scope pollution

Blocky DNSSEC validation bypass and validation-cache scope pollution

▾ Twilight0xERR0R · github.com/0xERR0R/blockyvia GHSA
GHSA-wfqx-gjrf-g28rCritical· 9.0
3mo ago

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

▾ Midnightcrossplane · github.com/crossplane/crossplane/v2via GHSA
CVE-2026-11769Medium
3mo ago

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operator/v5EPSS 0.36%via GHSA
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
CVE-2026-55185Medium
3mo ago

Open Redirect Bypass in miniflux-v2

Open Redirect Bypass in miniflux-v2

▾ Sunlitv2 · miniflux.app/v2EPSS 0.59%via GHSA
CVE-2026-55187Medium· 5.8
3mo ago

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.38%via GHSA
CVEs tagged “go” — page 27 · VulnSea