Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-32695MediumTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
CVE-2026-33748Medium· 6.5github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)
A flaw was found in BuildKit. Insufficient validation of Git URL fragment subdirectory components may allow a remote attacker to access files outside the checked-out Git repository root. This access is limited to files on the same mounted …
CVE-2026-33747High· 8.2BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747)
A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state …
CVE-2026-34204High· 7.1MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
CVE-2026-27877Medium· 6.5Grafana public dashboards disclose all direct mode datasources
Grafana public dashboards disclose all direct mode datasources
CVE-2026-28377High· 7.5Grafana Tempo has Inadequate Encryption Strength
Grafana Tempo has Inadequate Encryption Strength
CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message
OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode
OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2026-21724Medium· 5.4Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
CVE-2026-56765Critical· 9.1Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
CVE-2026-33487High· 7.5PoCgoxmlsig provides XML Digital Signatures implemented in Go
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…
CVE-2026-32285High· 7.5PoCThe Delete function fails to properly validate offsets when processing malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
CVE-2026-33809Medium· 5.3Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
CVE-2026-29785High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …
CVE-2026-33634CriticalCISA KEVPoCTrivy ecosystem supply chain was briefly compromised
Trivy ecosystem supply chain was briefly compromised
CVE-2026-33246Medium· 6.4NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
CVE-2026-33248Medium· 4.2NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
CVE-2026-54685Medium· 5.3FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVE-2026-33022Medium· 6.5github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names (CVE-2026-33022)
A denial of service flaw was found in Tekton Pipelines. Any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. …
CVE-2026-33322CriticalMinIO has JWT Algorithm Confusion in OIDC Authentication
MinIO has JWT Algorithm Confusion in OIDC Authentication
CVE-2026-33320Medium· 6.2PoCDasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
CVE-2026-26933Medium· 5.7Packetbeat does not properly validate an array index in multiple protocol parser components
Packetbeat does not properly validate an array index in multiple protocol parser components
CVE-2026-26931Medium· 5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
CVE-2026-32761Medium· 6.5File Browser has an Authorization Policy Bypass in Public Share Download Flow
File Browser has an Authorization Policy Bypass in Public Share Download Flow
CVE-2026-33066MediumSiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-30405High· 7.5GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
CVE-2026-28229High· 7.5Unauthorized access to Argo Workflows Template
Unauthorized access to Argo Workflows Template
CVE-2026-31892High· 8.5github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)
A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…