Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-7734Medium· 5.3GoBGP has an Improper Resource Shutdown or Release
GoBGP has an Improper Resource Shutdown or Release
CVE-2026-7736High· 7.3GoBGP has an Integer Underflow Issue
GoBGP has an Integer Underflow Issue
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…
CVE-2026-40280Critical· 9.3PoCGotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVE-2026-32936High· 7.5CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-32934High· 7.5CoreDNS' DoQ worker pool does not bound stream backlog
CoreDNS' DoQ worker pool does not bound stream backlog
CVE-2026-30246Medium· 6.5Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
CVE-2026-7020Medium· 5.6PoCOllama is Vulnerable to Path Traversal
Ollama is Vulnerable to Path Traversal
CVE-2026-6993Medium· 5.3go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)
A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…
CVE-2026-41327Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVE-2026-41492Critical· 9.8PoCDgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVE-2026-40912High· 8.2Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
CVE-2026-41328Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-40886High· 7.7Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
CVE-2026-32952Medium· 5.3go-ntlmssp NTLM challenges can panic on malformed payloads
go-ntlmssp NTLM challenges can panic on malformed payloads
CVE-2026-41179Critical· 9.8PoCRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
OpenFGA has Improper Policy Enforcement
CVE-2026-41282Medium· 5.3Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
CVE-2026-33812NoneExcessive memory allocation when decoding malicious SFNT in golang.org/x/image
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39946Medium· 4.9OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-40890High· 7.5github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…
CVE-2026-6634Medium· 6.3Memos has an Incorrect Privilege Assignment issue
Memos has an Incorrect Privilege Assignment issue
CVE-2026-41589Critical· 9.6Wish has SCP Path Traversal that allows arbitrary file read/write
Wish has SCP Path Traversal that allows arbitrary file read/write
CVE-2026-41491High· 8.1Dapr: Service Invocation path traversal ACL bypass
Dapr: Service Invocation path traversal ACL bypass
CVE-2026-41506Medium· 4.7go-git: Credential leak via cross-host redirect in smart HTTP transport
go-git: Credential leak via cross-host redirect in smart HTTP transport
CVE-2026-5052Medium· 5.3HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS