VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-11500Medium· 5.0
3mo ago

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

▾ Sunlitweaviate · github.com/weaviate/weaviateEPSS 0.34%via OSV
CVE-2026-11465Low· 3.1
3mo ago

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

▾ Sunlitsongquanpeng · github.com/songquanpeng/one-apiEPSS 0.22%via OSV
CVE-2026-11479Medium· 4.2
3mo ago

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlityoanbernabeu · github.com/yoanbernabeu/grepaiEPSS 0.16%via OSV
CVE-2026-47722High
3mo ago

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.47%via GHSA
CVE-2026-47723High
3mo ago

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.53%via GHSA
CVE-2026-47724Critical· 9.9
3mo ago

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

▾ Midnightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-47725High
3mo ago

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.22%via GHSA
CVE-2026-47726High
3mo ago

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.41%via GHSA
CVE-2026-41178High· 7.5
3mo ago

github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…

A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.34%via CSAF
CVE-2026-47703Medium
3mo ago

AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle

AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle

▾ SunlitAdguardTeam · github.com/AdguardTeam/AdGuardHomeEPSS 0.14%via OSV
CVE-2026-10814Medium· 4.5
3mo ago

milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery

milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery

▾ Sunlitmilvus-io · github.com/milvus-io/milvusEPSS 0.09%via OSV
CVE-2026-10722Low· 3.3
3mo ago

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

▾ Sunlitcilium · github.com/cilium/ebpfEPSS 0.18%via OSV
CVE-2026-37462High· 7.3
3mo ago

GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function

GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.49%via OSV
CVE-2026-40898Medium· 5.3
3mo ago

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

▾ Sunlitquic-go · github.com/quic-go/quic-goEPSS 0.49%via OSV
CVE-2026-42507Medium· 5.3
3mo ago

net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)

A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error m…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.41%via CSAF
CVE-2026-42504High· 7.5
3mo ago

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

▾ Twilightstdlib · stdlibEPSS 0.56%via OSV
CVE-2026-27145Medium· 6.5PoC
3mo ago

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…

▾ TwilightGo standard library · crypto/x509EPSS 0.59%via NVD
CVE-2026-48119High· 7.1
3mo ago

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.37%via OSV
CVE-2026-44740High· 7.5
3mo ago

github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)

A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation an…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-10219High· 7.3
3mo ago

GoClaw has a Command Injection issue

GoClaw has a Command Injection issue

▾ Twilightnextlevelbuilder · github.com/nextlevelbuilder/goclawEPSS 1.3%via OSV
CVE-2026-10517Medium· 5.8
3mo ago

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

▾ Sunlitquay · github.com/quay/claircorevia OSV
CVE-2026-42500None
4mo ago

Panic when reading out of bound palette index in golang.org/x/image/bmp

Panic when reading out of bound palette index in golang.org/x/image/bmp

▾ Sunlitx · golang.org/x/imageEPSS 0.52%via OSV
GHSA-w5pp-99ch-qj29Medium· 6.5
4mo ago

go-git: Malformed Git object data may cause panics or resource exhaustion

go-git: Malformed Git object data may cause panics or resource exhaustion

▾ Sunlitgo-git · github.com/go-git/go-git/v5via OSV
CVE-2026-6720High
4mo ago

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

▾ Twilightprojectcalico · github.com/projectcalico/calicoctl/v3EPSS 0.30%via OSV
CVE-2026-44973High· 8.1
4mo ago

github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)

A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…

▾ TwilightRed Hat · Multicluster Engine for KubernetesEPSS 0.47%via CSAF
CVE-2026-47179High· 7.7
4mo ago

Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives

Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives

▾ Twilightgetarcaneapp · github.com/getarcaneapp/arcane/backendEPSS 0.46%via OSV
CVE-2026-45287Low
4mo ago

opentelemetry-go's Schema ParseFile leaks file descriptors on each parse

opentelemetry-go's Schema ParseFile leaks file descriptors on each parse

▾ Sunlitotel · go.opentelemetry.io/otel/schema/v1.1EPSS 0.18%via OSV
CVE-2026-9094Critical· 9.8
4mo ago

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

▾ Midnightcasdoor · github.com/casdoor/casdoorEPSS 0.48%via OSV
CVE-2026-9804High· 7.7
4mo ago

A flaw was found in KubeVirt's virt-exportserver component

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an ex…

▾ TwilightRed Hat · container-native-virtualization/virt-exportserver-rhel9EPSS 0.72%via NVD
CVE-2026-45570Medium· 6.3
4mo ago

github.com/go-git/go-git: go-git: Shell command injection in SSH transport (CVE-2026-45570)

A flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to mani…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.17EPSS 0.43%via CSAF
CVEs tagged “go” — page 31 · VulnSea