VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2026-29049Medium· 4.3
6mo ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…

▾ Sunlitchainguard · melangeEPSS 0.39%via NVD
CVE-2026-27137High· 7.5
6mo ago

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…

▾ Twilightgolang · goEPSS 0.66%via NVD
CVE-2026-25679High· 7.5
6mo ago

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

▾ Twilightgolang · goEPSS 0.80%via NVD
CVE-2021-25320Critical· 9.9
6mo ago

Rancher cloud credentials can be used through proxy API by users without access

Rancher cloud credentials can be used through proxy API by users without access

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.85%via OSV
CVE-2022-21951Medium· 6.8
6mo ago

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

▾ Sunlitrancher · github.com/rancher/rancherEPSS 0.39%via OSV
CVE-2023-22648High· 8.0
6mo ago

Rancher's Azure AD permission changes are not reflected on active sessions

Rancher's Azure AD permission changes are not reflected on active sessions

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.45%via OSV
CVE-2021-36783Critical· 9.9
6mo ago

Rancher doesn't properly sanitize credentials in cluster template answers

Rancher doesn't properly sanitize credentials in cluster template answers

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2022-31247Critical· 9.1
6mo ago

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.98%via OSV
CVE-2026-22728Medium· 4.9
7mo ago

Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotat…

Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations

▾ Sunlitbitnami-labs · github.com/bitnami-labs/sealed-secretsEPSS 0.36%via OSV
CVE-2026-24834High· 8.8
7mo ago

Kata Container to Guest micro VM privilege escalation

Kata Container to Guest micro VM privilege escalation

▾ Twilightkata-containers · github.com/kata-containers/kata-containers/src/runtimeEPSS 0.22%via OSV
CVE-2026-27017Low
7mo ago

uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots

uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots

▾ Sunlitrefraction-networking · github.com/refraction-networking/utlsEPSS 0.19%via OSV
CVE-2025-67860Low· 3.8
7mo ago

NeuVector scanner insecurely handles passwords as command arguments

NeuVector scanner insecurely handles passwords as command arguments

▾ Sunlitneuvector · github.com/neuvector/scannerEPSS 0.09%via OSV
CVE-2026-21438Medium· 5.3
7mo ago

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

▾ Sunlitquic-go · github.com/quic-go/webtransport-goEPSS 0.38%via OSV
CVE-2026-26190Critical· 9.8PoC
7mo ago

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise

▾ Abyssalmilvus-io · github.com/milvus-io/milvusEPSS 4.0%via OSV
CVE-2026-25890High· 8.1PoC
7mo ago

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via OSV
CVE-2026-2303Medium· 6.5
7mo ago

mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling

mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling

▾ Sunlitmongo-driver · go.mongodb.org/mongo-driverEPSS 0.23%via OSV
CVE-2025-66630Critical
7mo ago

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

▾ Midnightgofiber · github.com/gofiber/fiber/v2EPSS 0.49%via OSV
CVE-2026-25934Medium· 4.3
7mo ago

go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files (CVE-2026-25934)

A flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.15%via CSAF
CVE-2026-25793High
7mo ago

Blocklist Bypass possible via ECDSA Signature Malleability

Blocklist Bypass possible via ECDSA Signature Malleability

▾ Twilightslackhq · github.com/slackhq/nebulaEPSS 0.17%via OSV
CVE-2025-68121None
7mo ago

Unexpected session resumption in crypto/tls

Unexpected session resumption in crypto/tls

▾ Sunlitstdlib · stdlibEPSS 0.86%via OSV
CVE-2026-24513Low· 3.1
7mo ago

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.32%via OSV
CVE-2026-25145Medium· 5.5
7mo ago

melange has a path traversal in license-path which allows reading files outside workspace

melange has a path traversal in license-path which allows reading files outside workspace

▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.18%via OSV
CVE-2026-24514Medium· 6.5PoC
7mo ago

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 0.49%via OSV
CVE-2026-25122Medium· 5.5
7mo ago

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.11%via OSV
CVE-2026-25121High· 7.5
7mo ago

apko has a path traversal in apko dirFS which allows filesystem writes outside base

apko has a path traversal in apko dirFS which allows filesystem writes outside base

▾ Twilightapko · chainguard.dev/apkoEPSS 0.39%via OSV
CVE-2025-61730Medium· 5.3
8mo ago

crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)

A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…

▾ SunlitRed Hat · Red Hat Ceph Storage 6EPSS 0.33%via CSAF
CVE-2025-61728None
8mo ago

Excessive CPU consumption when building archive index in archive/zip

Excessive CPU consumption when building archive index in archive/zip

▾ Sunlitstdlib · stdlibEPSS 0.75%via OSV
CVE-2025-11065Medium· 5.3
8mo ago

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input valu…

▾ Sunlitgo-viper · github.com/go-viper/mapstructure/v2EPSS 0.41%via NVD
CVE-2025-66719Critical· 9.1
8mo ago

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

▾ Midnightfree5gc · github.com/free5gc/nrfEPSS 0.35%via OSV
CVE-2026-24117Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)

A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a p…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.37%via CSAF
CVEs tagged “go” — page 39 · VulnSea