Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-11500Medium· 5.0Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
CVE-2026-11465Low· 3.1songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
CVE-2026-11479Medium· 4.2grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
CVE-2026-47722Highnebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
CVE-2026-47723Highnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
CVE-2026-47724Critical· 9.9nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
CVE-2026-47725Highnebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
CVE-2026-47726Highnebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
CVE-2026-41178High· 7.5github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denia…
A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length i…
CVE-2026-47703MediumAdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVE-2026-10814Medium· 4.5milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery
CVE-2026-10722Low· 3.3ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
CVE-2026-37462High· 7.3GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
CVE-2026-40898Medium· 5.3quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVE-2026-42507Medium· 5.3net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)
A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error m…
CVE-2026-42504High· 7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-27145Medium· 6.5PoC(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…
CVE-2026-48119High· 7.1Nezha's authenticated agents can forge service-monitor results for other users' services
Nezha's authenticated agents can forge service-monitor results for other users' services
CVE-2026-44740High· 7.5github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)
A flaw was found in Billy, an interface filesystem abstraction for Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing crafted or malformed input. The issue arises from insufficient validation an…
CVE-2026-10219High· 7.3GoClaw has a Command Injection issue
GoClaw has a Command Injection issue
CVE-2026-10517Medium· 5.8Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
CVE-2026-42500NonePanic when reading out of bound palette index in golang.org/x/image/bmp
Panic when reading out of bound palette index in golang.org/x/image/bmp
GHSA-w5pp-99ch-qj29Medium· 6.5go-git: Malformed Git object data may cause panics or resource exhaustion
go-git: Malformed Git object data may cause panics or resource exhaustion
CVE-2026-6720HighCalico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
CVE-2026-44973High· 8.1github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)
A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…
CVE-2026-47179High· 7.7Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
CVE-2026-45287Lowopentelemetry-go's Schema ParseFile leaks file descriptors on each parse
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
CVE-2026-9094Critical· 9.8Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
CVE-2026-9804High· 7.7A flaw was found in KubeVirt's virt-exportserver component
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an ex…
CVE-2026-45570Medium· 6.3github.com/go-git/go-git: go-git: Shell command injection in SSH transport (CVE-2026-45570)
A flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to mani…