Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2026-45692Medium· 5.4Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GHSA-mx64-mj3q-7prjHigh· 7.5iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
CVE-2026-18676MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-44283Medium· 4.3⚖ disputedetcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)
A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…
CVE-2026-45021MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-8634Critical· 9.1Crabbox: environment variable exposure vulnerability
Crabbox: environment variable exposure vulnerability
CVE-2026-44885Medium· 5.5Portainer has a path traversal in backup archive extraction that allows arbitrary file write
Portainer has a path traversal in backup archive extraction that allows arbitrary file write
GHSA-gxhx-2686-5h9gMediumslack-go `SecretsVerifier` accepts empty signing secret without precondition
slack-go `SecretsVerifier` accepts empty signing secret without precondition
CVE-2026-44697High· 8.6Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
CVE-2026-45152High· 7.8uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
CVE-2026-44477Critical· 9.9CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CVE-2026-8276Low· 3.7bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
CVE-2026-45022Highgo-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-6815Medium· 5.9PoCCasdoor: Arbitrary file write possible through Local File System storage provider
Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-44309Medium· 5.3gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
CVE-2026-44310Medium· 5.4gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVE-2026-44327Critical· 10.0free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
Rancher Extensions have arbitrary file access via path traversal
CVE-2026-79660Medium· 5.3Ech0 comment model's Email field returned on public /api/comments endpoints
Ech0 comment model's Email field returned on public /api/comments endpoints
CVE-2026-79668Medium· 5.3Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
CVE-2026-79661Medium· 6.5Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
CVE-2026-79662High· 8.0Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
CVE-2026-79663Medium· 4.8Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
CVE-2026-42501Medium· 5.3cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
A flaw was found in the Go command (`cmd/go`). A malicious module proxy can exploit this vulnerability by bypassing the validation of module checksums. This allows the proxy to serve altered versions of the Go toolchain, which the `go` com…
CVE-2026-39823Medium· 5.4html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)
A flaw was found in the `html/template` package of Go. A remote attacker could exploit this vulnerability by inserting ASCII whitespaces around the equals sign (`=`) within a URL's content attribute inside a `<meta>` tag. This improper esc…
CVE-2026-39826Medium· 5.4html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)
A flaw was found in html/template. A trusted template author could craft a script tag with an empty or whitespace-only 'type' attribute. This vulnerability causes the template engine to incorrectly escape data passed into the script block,…
CVE-2026-39817Medium· 5.9Invoking "go tool pack" does not sanitize output paths in cmd/go
Invoking "go tool pack" does not sanitize output paths in cmd/go
CVE-2026-39819Medium· 4.4Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
CVE-2026-39825Medium· 6.5net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2…
A flaw was found in the `net/http/httputil` package, specifically within the `ReverseProxy` component. This vulnerability allows the `ReverseProxy` to forward query parameters that are not visible to `Rewrite` functions. This occurs becaus…