Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-42592Medium· 5.3Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
CVE-2026-39836High· 7.5net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)
A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a speci…
CVE-2026-42328Medium· 6.2go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
CVE-2026-42285High· 7.5github.com/osrg/gobgp: GoBGP: Denial of Service due to specially crafted BGP UPDATE message (CVE-2026-42285)
A flaw was found in GoBGP 4.4.0. A crafted BGP UPDATE with inconsistent attribute lengths mishandles the withdraw state transition in AdjRib.Update, causing a nil pointer dereference and full process crash. Fixed in GoBGP 4.5.0.
CVE-2026-41642High· 7.5github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message (CVE-2026-41642)
A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.
CVE-2026-42597Medium· 5.9Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
GHSA-fpw6-hrg5-q5x5High· 7.4ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
CVE-2026-42590High· 8.2Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVE-2026-7461High· 7.2Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
CVE-2026-42880Critical· 9.6PoCArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-33814High· 7.5When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
CVE-2026-42499High· 7.5Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-39820High· 7.5Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-33811High· 7.5When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVE-2026-44301MediumHugo's Node tool execution allows file system access outside the project directory
Hugo's Node tool execution allows file system access outside the project directory
CVE-2026-44423Medium· 6.5ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
CVE-2025-71261High· 8.6Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly
OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-42554MediumFiber vulnerable to XSS in AutoFormat Content Negotiation
Fiber vulnerable to XSS in AutoFormat Content Negotiation
CVE-2026-44166MediumPoCPocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
GHSA-h5fq-653g-gxrmMedium· 5.3ots has a negative expire override that can bypass its secret retention policy
ots has a negative expire override that can bypass its secret retention policy
CVE-2026-7776High· 7.5Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVE-2026-42220Medium· 6.5Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and r…
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2026-7482Critical· 9.1PoCOllama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2026-42294High· 7.5Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVE-2026-42295HighArgo vulnerable to exposure of artifact repository credentials
Argo vulnerable to exposure of artifact repository credentials
CVE-2026-41888MediumDistribution's tag deletion bypasses `storage.delete.enabled` configuration
Distribution's tag deletion bypasses `storage.delete.enabled` configuration
CVE-2026-37461High· 7.5GoBGP has an out-of-bounds read in the ParseIP6Extended function
GoBGP has an out-of-bounds read in the ParseIP6Extended function
CVE-2026-7737Medium· 5.3GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer