VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

GHSA-46wh-3698-f2cxHigh
6mo ago

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

▾ Twilighttraefik · github.com/traefik/traefik/v2via OSV
CVE-2026-32695Medium
6mo ago

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.53%via OSV
CVE-2026-33748Medium· 6.5
6mo ago

github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)

A flaw was found in BuildKit. Insufficient validation of Git URL fragment subdirectory components may allow a remote attacker to access files outside the checked-out Git repository root. This access is limited to files on the same mounted …

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.53%via CSAF
CVE-2026-33747High· 8.2
6mo ago

BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747)

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.58%via CSAF
CVE-2026-34204High· 7.1
6mo ago

MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

▾ Twilightminio · github.com/minio/minioEPSS 0.21%via OSV
CVE-2026-27877Medium· 6.5
6mo ago

Grafana public dashboards disclose all direct mode datasources

Grafana public dashboards disclose all direct mode datasources

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.40%via OSV
CVE-2026-28377High· 7.5
6mo ago

Grafana Tempo has Inadequate Encryption Strength

Grafana Tempo has Inadequate Encryption Strength

▾ Twilightgrafana · github.com/grafana/tempoEPSS 0.16%via OSV
CVE-2026-33758Critical
6mo ago

OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao has Reflected XSS in its OIDC authentication error message

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.45%via OSV
CVE-2026-33757Critical· 9.6
6mo ago

OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao lacks user confirmation for OIDC direct callback mode

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.61%via OSV
CVE-2026-21724Medium· 5.4
6mo ago

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.26%via OSV
CVE-2026-56765Critical· 9.1
6mo ago

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

▾ Midnightapi · code.vikunja.io/apiEPSS 0.51%via OSV
CVE-2026-33487High· 7.5PoC
6mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

▾ Midnightgoxmldsig_project · goxmldsigEPSS 0.42%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-33809Medium· 5.3
6mo ago

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

▾ Sunlitx · golang.org/x/imageEPSS 0.39%via OSV
CVE-2026-29785High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …

▾ Twilightlinuxfoundation · nats-serverEPSS 0.97%via NVD
CVE-2026-33634CriticalCISA KEVPoC
6mo ago

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

▾ Hadalaquasecurity · github.com/aquasecurity/trivyEPSS 1.7%via OSV
CVE-2026-33246Medium· 6.4
6mo ago

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.24%via OSV
CVE-2026-33248Medium· 4.2
6mo ago

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.17%via OSV
CVE-2026-54685Medium· 5.3
6mo ago

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.47%via OSV
CVE-2026-33022Medium· 6.5
6mo ago

github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names (CVE-2026-33022)

A denial of service flaw was found in Tekton Pipelines. Any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. …

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.45%via CSAF
CVE-2026-33322Critical
6mo ago

MinIO has JWT Algorithm Confusion in OIDC Authentication

MinIO has JWT Algorithm Confusion in OIDC Authentication

▾ Midnightminio · github.com/minio/minioEPSS 0.61%via OSV
CVE-2026-33320Medium· 6.2PoC
6mo ago

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

▾ Twilighttomwright · github.com/tomwright/dasel/v3EPSS 0.17%via OSV
CVE-2026-26933Medium· 5.7
6mo ago

Packetbeat does not properly validate an array index in multiple protocol parser components

Packetbeat does not properly validate an array index in multiple protocol parser components

▾ Sunlitelastic · github.com/elastic/beats/v7EPSS 0.29%via OSV
CVE-2026-26931Medium· 5.7
6mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

▾ Sunlitelastic · metricbeatEPSS 0.29%via NVD
CVE-2026-32761Medium· 6.5
6mo ago

File Browser has an Authorization Policy Bypass in Public Share Download Flow

File Browser has an Authorization Policy Bypass in Public Share Download Flow

▾ Sunlithttps: · https://github.com/filebrowser/filebrowserEPSS 0.46%via OSV
CVE-2026-33066Medium
6mo ago

SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering

SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.68%via OSV
CVE-2026-56397Medium
6mo ago

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.70%via GHSA
CVE-2026-30405High· 7.5
6mo ago

GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute

GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.55%via OSV
CVE-2026-28229High· 7.5
6mo ago

Unauthorized access to Argo Workflows Template

Unauthorized access to Argo Workflows Template

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.78%via OSV
CVE-2026-31892High· 8.5
6mo ago

github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)

A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.65%via CSAF
CVEs tagged “go” — page 38 · VulnSea