Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-54096HighFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-54092High· 6.5File Browser has a DoS Vulnerability via Public Login API
File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094Medium· 6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-54093MediumFile Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54091High· 7.5File Browser has incorrect access control for public directory shares via rule path rebasing
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-54090HighFile Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-48020HighPoCTraefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-48089HighDevGuard has improper authorization on public assets
DevGuard has improper authorization on public assets
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
CVE-2026-11401High· 8.0AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-25700High· 7.2Apache Answer: AdminToken not invalidated after admin deactivation
Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-53474Critical· 9.6Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
CVE-2026-53475Critical· 9.3Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
CVE-2026-53476Critical· 9.6Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
CVE-2026-53470Critical· 9.6Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
CVE-2026-53469Critical· 9.1Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
CVE-2026-53471Critical· 9.6Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-48025Mediumnebula-mesh: Decrypted CA private key persists in heap after signing
nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-48058Mediumnebula-mesh: Session and OIDC state cookies lack the Secure attribute
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-47768Medium· 5.5nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-34033Medium· 5.4Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
CVE-2026-25688Medium· 6.1Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
GHSA-7qjx-gp9h-65qjHigh· 8.7Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
CVE-2026-11481Low· 2.5grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm