VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-54096High
3mo ago

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.18%via GHSA
CVE-2026-54092High· 6.5
3mo ago

File Browser has a DoS Vulnerability via Public Login API

File Browser has a DoS Vulnerability via Public Login API

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-54094Medium· 6.8
3mo ago

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.50%via GHSA
CVE-2026-54093Medium
3mo ago

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.19%via GHSA
CVE-2026-54091High· 7.5
3mo ago

File Browser has incorrect access control for public directory shares via rule path rebasing

File Browser has incorrect access control for public directory shares via rule path rebasing

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.52%via GHSA
CVE-2026-54090High
3mo ago

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.44%via GHSA
CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-48089High
3mo ago

DevGuard has improper authorization on public assets

DevGuard has improper authorization on public assets

▾ Twilightl3montree-dev · github.com/l3montree-dev/devguardEPSS 0.36%via GHSA
CVE-2026-48096Medium· 5.0
3mo ago

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.13%via OSV
CVE-2026-11401High· 8.0
3mo ago

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightaws · github.com/aws/aws-advanced-go-wrapper/awssql/v2EPSS 0.30%via GHSA
CVE-2026-25700High· 7.2
3mo ago

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

▾ Twilightapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-53474Critical· 9.6
3mo ago

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53475Critical· 9.3
3mo ago

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

▾ Midnightkubev2v · github.com/kubev2v/assisted-migration-agentEPSS 0.50%via OSV
CVE-2026-53476Critical· 9.6
3mo ago

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

▾ Midnightkubev2v · github.com/kubev2v/assisted-migration-agentEPSS 0.43%via OSV
CVE-2026-53470Critical· 9.6
3mo ago

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.48%via OSV
CVE-2026-53469Critical· 9.1
3mo ago

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53471Critical· 9.6
3mo ago

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-49396High· 7.1
3mo ago

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.17%via GHSA
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.34%via GHSA
CVE-2026-48025Medium
3mo ago

nebula-mesh: Decrypted CA private key persists in heap after signing

nebula-mesh: Decrypted CA private key persists in heap after signing

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.51%via GHSA
CVE-2026-48058Medium
3mo ago

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.32%via GHSA
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.15%via GHSA
CVE-2026-34031Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.64%via OSV
CVE-2026-33582Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-34905Medium· 6.5
3mo ago

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.51%via OSV
CVE-2026-34033Medium· 5.4
3mo ago

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.52%via OSV
CVE-2026-25699Medium· 6.1
3mo ago

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
CVE-2026-25688Medium· 6.1
3mo ago

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
GHSA-7qjx-gp9h-65qjHigh· 8.7
3mo ago

Dex: Token-exchange endpoint is missing AllowedConnectors enforcement

Dex: Token-exchange endpoint is missing AllowedConnectors enforcement

▾ Twilightdexidp · github.com/dexidp/dexvia GHSA
CVE-2026-11481Low· 2.5
3mo ago

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlityoanbernabeu · github.com/yoanbernabeu/grepaiEPSS 0.08%via OSV
CVEs tagged “go” — page 30 · VulnSea