Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-35594Medium· 6.5Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
CVE-2026-34727High· 7.4Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
CVE-2026-39414HighMinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVE-2026-39901Medium· 5.7monetr: Protected Transactions Deletable via PUT
monetr: Protected Transactions Deletable via PUT
CVE-2026-35607High· 8.1File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
CVE-2026-39429High· 8.2kcp's cache server is accessible without authentication or authorization checks
kcp's cache server is accessible without authentication or authorization checks
CVE-2026-32289Medium· 5.4html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals (CVE…
A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be inco…
CVE-2026-32281Medium· 5.9crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive r…
CVE-2026-32282High· 7.8golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…
GHSA-xmrv-pmrh-hhx2Medium· 5.9Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
CVE-2026-39882High· 7.5⚖ disputedgithub.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading (CVE-2026-39882)
A flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) a…
CVE-2026-32283High· 7.5If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects T…
CVE-2026-32280High· 7.5During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct u…
CVE-2026-33810High· 8.2When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted ce…
CVE-2026-33816High· 8.3github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816)
A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This memory-safety vulnerability could allow an attacker to cause various impacts, such as denial of service (DoS) or potentially arbitrary code execution, by exploiting…
CVE-2026-33815High· 8.3github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)
A flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.
CVE-2026-33540High· 7.5Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
CVE-2026-34972Medium· 4.2github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)
A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcemen…
CVE-2026-35480Medium· 6.2go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
CVE-2026-34986High· 7.5Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and …
CVE-2026-35166MediumHugo: Certain markdown links are not properly escaped
Hugo: Certain markdown links are not properly escaped
CVE-2026-34976Critical· 10.0PoCDgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVE-2026-4370Critical· 10.0Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
CVE-2026-34783High· 8.1Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
CVE-2026-34742High· 8.1DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
CVE-2026-5199LowTemporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same …
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
CVE-2026-34040High· 8.4PoCMoby: Moby: Authorization bypass vulnerability (CVE-2026-34040)
A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…
CVE-2026-33030High· 8.8nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
CVE-2026-27018HighGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
CVE-2026-32287High· 7.5XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion