VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-7734Medium· 5.3
4mo ago

GoBGP has an Improper Resource Shutdown or Release

GoBGP has an Improper Resource Shutdown or Release

▾ Sunlitosrg · github.com/osrg/gobgp/v4EPSS 0.85%via OSV
CVE-2026-7736High· 7.3
4mo ago

GoBGP has an Integer Underflow Issue

GoBGP has an Integer Underflow Issue

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.63%via OSV
CVE-2026-42151High· 7.5
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…

▾ Twilightprometheus · prometheusEPSS 0.41%via NVD
CVE-2026-40280Critical· 9.3PoC
5mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

▾ Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 2.1%via OSV
CVE-2026-41643High· 7.5
5mo ago

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.60%via OSV
CVE-2026-32936High· 7.5
5mo ago

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.61%via OSV
CVE-2026-32934High· 7.5
5mo ago

CoreDNS' DoQ worker pool does not bound stream backlog

CoreDNS' DoQ worker pool does not bound stream backlog

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.63%via OSV
CVE-2026-30246Medium· 6.5
5mo ago

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.37%via OSV
CVE-2026-7020Medium· 5.6PoC
5mo ago

Ollama is Vulnerable to Path Traversal

Ollama is Vulnerable to Path Traversal

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.90%via OSV
CVE-2026-6993Medium· 5.3
5mo ago

go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.54%via CSAF
CVE-2026-41327Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.47%via OSV
CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.5%via OSV
CVE-2026-40912High· 8.2
5mo ago

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.72%via OSV
CVE-2026-41328Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.48%via OSV
CVE-2026-40886High· 7.7
5mo ago

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.59%via OSV
CVE-2026-32952Medium· 5.3
5mo ago

go-ntlmssp NTLM challenges can panic on malformed payloads

go-ntlmssp NTLM challenges can panic on malformed payloads

▾ SunlitAzure · github.com/Azure/go-ntlmsspEPSS 1.5%via OSV
CVE-2026-41179Critical· 9.8PoC
5mo ago

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

▾ Abyssalrclone · github.com/rclone/rcloneEPSS 5.3%via OSV
CVE-2026-41131Medium· 5.0
5mo ago

OpenFGA has Improper Policy Enforcement

OpenFGA has Improper Policy Enforcement

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.23%via OSV
CVE-2026-41282Medium· 5.3
5mo ago

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

▾ Sunlitprojectdiscovery · github.com/projectdiscovery/nuclei/v3EPSS 0.43%via OSV
CVE-2026-33812None
5mo ago

Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

▾ Sunlitx · golang.org/x/imageEPSS 0.16%via OSV
CVE-2026-39396Low· 3.1
5mo ago

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.33%via OSV
CVE-2026-40264Low
5mo ago

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.36%via OSV
CVE-2026-39388Low· 3.1
5mo ago

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.14%via OSV
CVE-2026-39946Medium· 4.9
5mo ago

OpenBao's SQL Injection in PostgreSQL database secrets engine

OpenBao's SQL Injection in PostgreSQL database secrets engine

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.39%via OSV
CVE-2026-40890High· 7.5
5mo ago

github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…

▾ TwilightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.52%via CSAF
CVE-2026-6634Medium· 6.3
5mo ago

Memos has an Incorrect Privilege Assignment issue

Memos has an Incorrect Privilege Assignment issue

▾ Sunlitusememos · github.com/usememos/memosEPSS 0.35%via OSV
CVE-2026-41589Critical· 9.6
5mo ago

Wish has SCP Path Traversal that allows arbitrary file read/write

Wish has SCP Path Traversal that allows arbitrary file read/write

▾ Midnightwish · charm.land/wish/v2EPSS 0.51%via OSV
CVE-2026-41491High· 8.1
5mo ago

Dapr: Service Invocation path traversal ACL bypass

Dapr: Service Invocation path traversal ACL bypass

▾ Twilightdapr · github.com/dapr/daprEPSS 0.49%via OSV
CVE-2026-41506Medium· 4.7
5mo ago

go-git: Credential leak via cross-host redirect in smart HTTP transport

go-git: Credential leak via cross-host redirect in smart HTTP transport

▾ Sunlitgo-git · github.com/go-git/go-git/v5EPSS 0.26%via OSV
CVE-2026-5052Medium· 5.3
5mo ago

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.39%via OSV
CVEs tagged “go” — page 35 · VulnSea