Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2026-29049Medium· 4.3melange allows users to build apk packages using declarative pipelines
melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cac…
CVE-2026-27137High· 7.5When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the l…
CVE-2026-25679High· 7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2022-21951Medium· 6.8Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
CVE-2023-22648High· 8.0Rancher's Azure AD permission changes are not reflected on active sessions
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2022-31247Critical· 9.1Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2026-22728Medium· 4.9Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotat…
Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations
CVE-2026-24834High· 8.8Kata Container to Guest micro VM privilege escalation
Kata Container to Guest micro VM privilege escalation
CVE-2026-27017LowuTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
CVE-2025-67860Low· 3.8NeuVector scanner insecurely handles passwords as command arguments
NeuVector scanner insecurely handles passwords as command arguments
CVE-2026-21438Medium· 5.3webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
CVE-2026-26190Critical· 9.8PoCMilvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
CVE-2026-25890High· 8.1PoCFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
CVE-2026-2303Medium· 6.5mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling
mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling
CVE-2025-66630CriticalFiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
CVE-2026-25934Medium· 4.3go-git/go-git: go-git: Data integrity issue due to improper verification of pack and index files (CVE-2026-25934)
A flaw was found in go-git, a library for Git implementation in Go. This vulnerability allows a remote attacker to provide specially crafted Git pack or index files that are not properly verified for data integrity. Successful exploitation…
CVE-2026-25793HighBlocklist Bypass possible via ECDSA Signature Malleability
Blocklist Bypass possible via ECDSA Signature Malleability
CVE-2025-68121NoneUnexpected session resumption in crypto/tls
Unexpected session resumption in crypto/tls
CVE-2026-24513Low· 3.1ingress-nginx has Improper Check for Unusual or Exceptional Conditions
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
CVE-2026-25145Medium· 5.5melange has a path traversal in license-path which allows reading files outside workspace
melange has a path traversal in license-path which allows reading files outside workspace
CVE-2026-24514Medium· 6.5PoCingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2026-25122Medium· 5.5apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
CVE-2026-25121High· 7.5apko has a path traversal in apko dirFS which allows filesystem writes outside base
apko has a path traversal in apko dirFS which allows filesystem writes outside base
CVE-2025-61730Medium· 5.3crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)
A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…
CVE-2025-61728NoneExcessive CPU consumption when building archive index in archive/zip
Excessive CPU consumption when building archive index in archive/zip
CVE-2025-11065Medium· 5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input valu…
CVE-2025-66719Critical· 9.1Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
CVE-2026-24117Medium· 5.3github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)
A Server-Side Request Forgery (SSRF) flaw has been discovered in the Rekor transparency log tool. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a p…