VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-42592Medium· 5.3
4mo ago

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

▾ Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.25%via OSV
CVE-2026-39836High· 7.5
4mo ago

net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)

A flaw was found in the `net` package of Go (golang). When running on Windows, the `Dial` and `LookupPort` functions can panic if they receive an input containing a NUL (0) byte. This can be triggered by a remote attacker providing a speci…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.62%via CSAF
CVE-2026-42328Medium· 6.2
4mo ago

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

▾ Sunlitipld · github.com/ipld/go-ipld-primeEPSS 0.16%via OSV
CVE-2026-42285High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service due to specially crafted BGP UPDATE message (CVE-2026-42285)

A flaw was found in GoBGP 4.4.0. A crafted BGP UPDATE with inconsistent attribute lengths mishandles the withdraw state transition in AdjRib.Update, causing a nil pointer dereference and full process crash. Fixed in GoBGP 4.5.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVE-2026-41642High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message (CVE-2026-41642)

A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVE-2026-42597Medium· 5.9
4mo ago

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme

▾ Sunlitgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.36%via OSV
GHSA-fpw6-hrg5-q5x5High· 7.4
4mo ago

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

▾ Twilightlin-snow · github.com/lin-snow/ech0via OSV
CVE-2026-42590High· 8.2
4mo ago

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist

▾ Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.44%via OSV
CVE-2026-7461High· 7.2
4mo ago

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure

Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure

▾ Twilightaws · github.com/aws/amazon-ecs-agentEPSS 0.81%via OSV
CVE-2026-42880Critical· 9.6PoC
4mo ago

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

▾ Abyssalargoproj · github.com/argoproj/argo-cd/v3EPSS 0.56%via OSV
CVE-2026-33814High· 7.5
4mo ago

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

▾ Twilightgolang · goEPSS 0.78%via NVD
CVE-2026-42499High· 7.5
4mo ago

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

▾ Twilightgolang · goEPSS 0.80%via NVD
CVE-2026-39820High· 7.5
4mo ago

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

▾ Twilightgolang · goEPSS 0.87%via NVD
CVE-2026-33811High· 7.5
4mo ago

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

▾ Twilightgolang · goEPSS 0.88%via NVD
CVE-2026-44301Medium
4mo ago

Hugo's Node tool execution allows file system access outside the project directory

Hugo's Node tool execution allows file system access outside the project directory

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.43%via OSV
CVE-2026-44423Medium· 6.5
4mo ago

ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data

ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data

▾ Sunlitshellhub-io · github.com/shellhub-io/shellhubEPSS 0.35%via OSV
CVE-2025-71261High· 8.6
4mo ago

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

▾ Twilightharvester · github.com/harvester/harvesterEPSS 0.21%via OSV
CVE-2026-42186Low
4mo ago

OpenBao's Namespace Deletion May Not Delete Data Properly

OpenBao's Namespace Deletion May Not Delete Data Properly

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.43%via OSV
CVE-2026-42554Medium
4mo ago

Fiber vulnerable to XSS in AutoFormat Content Negotiation

Fiber vulnerable to XSS in AutoFormat Content Negotiation

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.31%via OSV
CVE-2026-44166MediumPoC
4mo ago

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

▾ Twilightpocketbase · github.com/pocketbase/pocketbaseEPSS 0.32%via OSV
GHSA-h5fq-653g-gxrmMedium· 5.3
4mo ago

ots has a negative expire override that can bypass its secret retention policy

ots has a negative expire override that can bypass its secret retention policy

▾ SunlitLuzifer · github.com/Luzifer/otsvia OSV
CVE-2026-7776High· 7.5
4mo ago

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

▾ Twilighthashicorp · github.com/hashicorp/boundaryEPSS 0.34%via OSV
CVE-2026-42220Medium· 6.5
4mo ago

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and r…

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback

▾ Sunlit0xJacky · github.com/0xJacky/Nginx-UIEPSS 0.40%via OSV
CVE-2026-41181Medium
4mo ago

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.50%via OSV
CVE-2026-7482Critical· 9.1PoC
4mo ago

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

▾ Abyssalollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2026-42294High· 7.5
4mo ago

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.74%via OSV
CVE-2026-42295High
4mo ago

Argo vulnerable to exposure of artifact repository credentials

Argo vulnerable to exposure of artifact repository credentials

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.40%via OSV
CVE-2026-41888Medium
4mo ago

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

▾ Sunlitdistribution · github.com/distribution/distribution/v3EPSS 0.35%via OSV
CVE-2026-37461High· 7.5
4mo ago

GoBGP has an out-of-bounds read in the ParseIP6Extended function

GoBGP has an out-of-bounds read in the ParseIP6Extended function

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.61%via OSV
CVE-2026-7737Medium· 5.3
4mo ago

GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer

GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer

▾ Sunlitosrg · github.com/osrg/gobgpEPSS 0.90%via OSV
CVEs tagged “go” — page 34 · VulnSea