Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-61554High· 7.5PoCemp3r0r is a C2 designed by Linux users for Linux environments
emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenti…
GHSA-rf68-8gjr-36q7LowNezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
CVE-2026-32599Medium· 5.3Netmaker makes networks with WireGuard
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an au…
CVE-2026-63443High· 8.3Coder allows organizations to provision remote development environments via Terraform
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…
CVE-2026-59157Medium· 6.5webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests
webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…
CVE-2026-54167High· 8.2Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …
CVE-2026-55149High· 7.5PoCVouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module
Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the val…
CVE-2026-53941Medium· 6.9Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…
CVE-2026-53658Medium· 6.3Fabric CA is a Certificate Authority for Hyperledger Fabric
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDA…
CVE-2026-49446Medium· 6.1PoCCosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…
CVE-2026-52724Medium· 5.8Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer ve…
CVE-2026-50166Medium· 5.5Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-ce…
CVE-2026-58196Medium· 4.7PoCToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer…
CVE-2026-54450Low· 2.9ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff…
CVE-2026-61549Critical· 9.0Woodpecker is a CI/CD engine
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pip…
CVE-2026-44300High· 8.8OpenCost provides cost monitoring for Kubernetes workloads and cloud costs
OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and s…
CVE-2026-47780Medium· 6.9PoCfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regul…
CVE-2026-54637Medium· 5.5PoCDragonfly is an open source P2P-based file distribution and image acceleration system
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through…
CVE-2026-49254Low· 2.9Dragonfly is an open source P2P-based file distribution and image acceleration system
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/h…
CVE-2026-55636Medium· 5.7Capsule is a multi-tenancy and policy-based framework for Kubernetes
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name…
CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server stru…
CVE-2026-44778Low· 2.9⚖ disputedInspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivi…
CVE-2026-48785Medium· 4.8Apptainer is an open source container platform
Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also author…
CVE-2026-55828Medium· 6.0qbee transport is a remote access transport protocol implementation
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A c…
CVE-2026-55770Medium· 6.8PoCOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…
CVE-2026-55774Low· 2.1OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…
CVE-2026-55775Low· 2.3⚖ disputedOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…
CVE-2026-55776Medium· 6.5PoCOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…
CVE-2026-55701Medium· 6.9The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector
The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiv…