Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2026-52844High· 7.5Caddy: Windows `file_server` path authorization bypass via encoded backslash
Caddy: Windows `file_server` path authorization bypass via encoded backslash
CVE-2026-52845High· 8.1Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVE-2026-52846Medium· 4.2Caddy: stripHTML template function bypass
Caddy: stripHTML template function bypass
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
CVE-2026-28744High· 8.1Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
CVE-2026-49980Critical· 9.8Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
CVE-2026-52797High· 8.5Gogs: Overwriting critical files results in a denial of service
Gogs: Overwriting critical files results in a denial of service
CVE-2026-28699High· 8.1PoCGitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
CVE-2026-26231High· 8.5Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
CVE-2026-25714Medium· 4.3Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
CVE-2026-27783Medium· 4.3Gitea: Missing repository-unit authorization on issue-template API endpoints
Gitea: Missing repository-unit authorization on issue-template API endpoints
CVE-2026-20706MediumGitea: Token scope bypass on web archive download endpoint
Gitea: Token scope bypass on web archive download endpoint
CVE-2026-50891High· 8.1Filestash allows attackers to escalate privileges via sending a crafted request
Filestash allows attackers to escalate privileges via sending a crafted request
CVE-2026-50884High· 8.8statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
CVE-2026-50879High· 7.5linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST r…
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
CVE-2026-11624CriticalMCP Toolbox for Databases has an Origin Validation Error
MCP Toolbox for Databases has an Origin Validation Error
GHSA-v82c-5c2q-hx9gMediumDuplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2026-42306High· 7.2github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup (…
A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary …
CVE-2026-12681Medium· 6.8Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
GHSA-9r4w-jg96-92mvMedium· 6.8Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
GHSA-6vgg-xhvh-38ffLownebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
CVE-2026-53999High· 7.7Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
CVE-2026-54097HighFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix