Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
GHSA-6vxv-wg6j-5qwpHighGogs: XSS in .ipynb files renderer due to outdated notebookjs
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
CVE-2026-57209HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
CVE-2026-57210HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
CVE-2026-56664Medium· 4.2ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-55671LowZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
CVE-2026-55229High· 7.5PoCGotenberg: SSRF via LibreOffice document processing
Gotenberg: SSRF via LibreOffice document processing
CVE-2026-55670LowZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
CVE-2026-55672High· 7.4ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
GHSA-wxg7-w2v3-w38gMedium· 4.2ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-55669Medium· 4.2ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
CVE-2026-11717Criticalgoogleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11718Criticalgoogleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11719HighMCP Toolbox for Databases: authenticated authorization bypass
MCP Toolbox for Databases: authenticated authorization bypass
GHSA-38x9-25wx-7fg2HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
GHSA-4jgr-pg2m-m988HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
CVE-2026-55686Medium· 5.3Podman: WORKDIR symlink traversal vulnerability
Podman: WORKDIR symlink traversal vulnerability
CVE-2026-55170LowOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVE-2026-22555High· 8.1Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
CVE-2026-24791High· 8.1Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-28737High· 8.7Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
CVE-2026-25779MediumGitea: Open Redirect via redirect_to
Gitea: Open Redirect via redirect_to
CVE-2026-48491HighTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
CVE-2026-50133MediumHugo: XSS via text/html content files
Hugo: XSS via text/html content files
CVE-2026-50134MediumHugo: security.http.urls allow-list bypass via HTTP redirects
Hugo: security.http.urls allow-list bypass via HTTP redirects
CVE-2026-50135MediumHugo: Symlink confinement bypass in resources.Get
Hugo: Symlink confinement bypass in resources.Get
CVE-2026-53622HighTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private
Daytona: Public sandbox previews remain accessible for up to one hour after being made private