Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2026-5807High· 7.5HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVE-2026-4525High· 7.5HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
CVE-2026-40293High· 7.5OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)
A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…
CVE-2026-5160Medium· 6.1goldmark vulnerable to Cross-site Scripting (XSS)
goldmark vulnerable to Cross-site Scripting (XSS)
CVE-2026-40173Critical· 9.4Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
CVE-2026-40611High· 8.8ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
CVE-2026-41068High· 7.7Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
CVE-2024-53412High· 8.4NietThijmen ShoppingCart: Command injection in the connect function
NietThijmen ShoppingCart: Command injection in the connect function
CVE-2026-40574Medium· 6.8OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
CVE-2026-40575Critical· 9.1OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-21726Medium· 5.3Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
CVE-2026-40090High· 7.1Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
CVE-2026-40246High· 7.5free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVE-2026-40922Medium· 5.4SiYuan has incomplete fix for CVE-2026-33066: XSS
SiYuan has incomplete fix for CVE-2026-33066: XSS
CVE-2026-34476High· 7.1Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
CVE-2026-79671Medium· 5.5Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
CVE-2026-79673Medium· 6.5Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
CVE-2026-79672Medium· 5.5Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
CVE-2026-79666Medium· 6.5Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
CVE-2026-79670Medium· 4.8Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
CVE-2026-79667High· 7.6Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
CVE-2026-34178Critical· 9.1LXD: Importing a crafted backup leads to project restriction bypass
LXD: Importing a crafted backup leads to project restriction bypass
CVE-2026-34177Critical· 9.1LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
CVE-2026-34179Critical· 9.1LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
CVE-2026-35204High· 8.6PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVE-2026-35205High· 7.8Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVE-2026-35206MediumHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2026-35596Medium· 4.3Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
CVE-2026-35597Medium· 5.9Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
CVE-2026-40242High· 7.2PoCArcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint