VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-35594Medium· 6.5
5mo ago

Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.44%via OSV
CVE-2026-34727High· 7.4
5mo ago

Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path

Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path

▾ Twilightapi · code.vikunja.io/apiEPSS 0.42%via OSV
CVE-2026-39414High
5mo ago

MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

▾ Twilightminio · github.com/minio/minioEPSS 0.56%via OSV
CVE-2026-39901Medium· 5.7
5mo ago

monetr: Protected Transactions Deletable via PUT

monetr: Protected Transactions Deletable via PUT

▾ Sunlitmonetr · github.com/monetr/monetrEPSS 0.33%via OSV
CVE-2026-35607High· 8.1
5mo ago

File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.56%via OSV
CVE-2026-39429High· 8.2
5mo ago

kcp's cache server is accessible without authentication or authorization checks

kcp's cache server is accessible without authentication or authorization checks

▾ Twilightkcp-dev · github.com/kcp-dev/kcpEPSS 0.54%via OSV
CVE-2026-32289Medium· 5.4
5mo ago

html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals (CVE…

A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be inco…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CVE-2026-32281Medium· 5.9
5mo ago

crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive r…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.37%via CSAF
CVE-2026-32282High· 7.8
5mo ago

golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)

A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.17%via CSAF
GHSA-xmrv-pmrh-hhx2Medium· 5.9
5mo ago

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

▾ Sunlitaws · github.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamvia OSV
CVE-2026-39882High· 7.5⚖ disputed
5mo ago

github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading (CVE-2026-39882)

A flaw was found in OpenTelemetry-Go. The otlp HTTP exporters read the full HTTP response body into an in-memory buffer without a size cap. A remote attacker, by controlling the collector endpoint or performing a man-in-the-middle (MITM) a…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.22EPSS 0.19%via CSAF
CVE-2026-32283High· 7.5
5mo ago

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects T…

▾ Twilightgolang · goEPSS 0.67%via NVD
CVE-2026-32280High· 7.5
5mo ago

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct u…

▾ Twilightgolang · goEPSS 0.70%via NVD
CVE-2026-33810High· 8.2
5mo ago

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted ce…

▾ Twilightgolang · goEPSS 0.34%via NVD
CVE-2026-33816High· 8.3
5mo ago

github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816)

A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This memory-safety vulnerability could allow an attacker to cause various impacts, such as denial of service (DoS) or potentially arbitrary code execution, by exploiting…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.86%via CSAF
CVE-2026-33815High· 8.3
5mo ago

github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)

A flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.86%via CSAF
CVE-2026-33540High· 7.5
5mo ago

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

▾ Twilightdistribution · github.com/distribution/distribution/v3EPSS 0.39%via OSV
CVE-2026-34972Medium· 4.2
5mo ago

github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)

A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcemen…

▾ SunlitRed Hat · Multicluster Global HubEPSS 0.27%via CSAF
CVE-2026-35480Medium· 6.2
5mo ago

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

▾ Sunlitipld · github.com/ipld/go-ipld-primeEPSS 0.16%via OSV
CVE-2026-34986High· 7.5
5mo ago

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and …

▾ Twilightgo-jose_project · go-joseEPSS 0.76%via NVD
CVE-2026-35166Medium
5mo ago

Hugo: Certain markdown links are not properly escaped

Hugo: Certain markdown links are not properly escaped

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.23%via OSV
CVE-2026-34976Critical· 10.0PoC
5mo ago

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 1.7%via OSV
CVE-2026-4370Critical· 10.0
5mo ago

Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster

Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster

▾ Midnightjuju · github.com/juju/jujuEPSS 0.41%via OSV
CVE-2026-34783High· 8.1
6mo ago

Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites

▾ TwilightMontFerret · github.com/MontFerret/ferret/v2EPSS 0.71%via OSV
CVE-2026-34742High· 8.1
6mo ago

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

▾ Twilightmodelcontextprotocol · github.com/modelcontextprotocol/go-sdkEPSS 0.66%via OSV
CVE-2026-5199Low
6mo ago

Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same …

Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster

▾ Sunlitserver · go.temporal.io/serverEPSS 0.30%via OSV
CVE-2026-34040High· 8.4PoC
6mo ago

Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…

▾ MidnightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.16%via CSAF
CVE-2026-33030High· 8.8
6mo ago

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

▾ Twilight0xJacky · github.com/0xJacky/nginx-uiEPSS 0.38%via OSV
CVE-2026-27018High
6mo ago

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)

▾ Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 1.6%via OSV
CVE-2026-32287High· 7.5
6mo ago

XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

▾ Twilightantchfx · github.com/antchfx/xpathEPSS 0.69%via OSV
CVEs tagged “go” — page 37 · VulnSea