Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-25680Medium· 6.5Go Net HTML parser is vulnerable to denial of service
Go Net HTML parser is vulnerable to denial of service
CVE-2026-7374Critical· 9.9A flaw was found in KubeVirt's virt-handler component
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine consol…
CVE-2026-42502Medium· 6.1Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-27136NoneInvoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-25681NoneInvoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2026-39821Critical· 9.6The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior …
CVE-2026-46598Medium· 5.3Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2026-39833Medium· 5.5⚖ disputedgolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)
A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before u…
CVE-2026-39832Critical· 9.1When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…
CVE-2026-46597High· 7.5Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-39828Medium· 6.3⚖ disputedInvoking bypass of certificate restrictions in golang.org/x/crypto/ssh
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…
CVE-2026-39835Medium· 5.3SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these…
CVE-2026-39827Medium· 6.5Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
CVE-2026-39830Critical· 9.1A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…
CVE-2026-39829High· 7.5The RSA and DSA public key parsers did not enforce size limits on key parameters
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This …
CVE-2026-39831High· 8.1golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)
A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…
CVE-2026-42508Critical· 9.1Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-39834Medium· 6.5⚖ disputedInvoking infinite loop on large channel writes in golang.org/x/crypto/ssh
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
CVE-2026-46595High· 7.1PoC⚖ disputedgolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…
CVE-2026-46612High· 8.8Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVE-2026-46617HighFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code names…
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
CVE-2026-45781Low· 3.5MCP Registry: OCI validator skips ownership check on upstream rate limits
MCP Registry: OCI validator skips ownership check on upstream rate limits
CVE-2026-45712Medium· 5.9Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVE-2026-45711Medium· 5.9Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVE-2026-45709Medium· 5.8Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
CVE-2026-45713High· 7.5Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
GHSA-wwhq-w58m-w29cMediumCaddy CVE-2026-30852 Fix Bypass
Caddy CVE-2026-30852 Fix Bypass
GHSA-gx7w-56w6-g48xMedium· 4.3Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-45571Medium· 5.4go-git: Crafted repositories may modify main and submodule .git directories
go-git: Crafted repositories may modify main and submodule .git directories
GHSA-g53w-w6mj-hrppCriticalMCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path