VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-23831Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor denial of service (CVE-2026-23831)

Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Ca…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.44%via CSAF
CVE-2026-23991Medium· 5.9
8mo ago

github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response (CVE-2026-23991)

A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial o…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.59%via CSAF
CVE-2026-23990Medium· 5.3
8mo ago

Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims

Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims

▾ Sunlitcontrolplaneio-fluxcd · github.com/controlplaneio-fluxcd/flux-operatorEPSS 0.35%via OSV
CVE-2026-23849Medium· 5.3
8mo ago

File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login

File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowserEPSS 0.49%via OSV
CVE-2026-23644High
8mo ago

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

▾ Twilightesm-dev · github.com/esm-dev/esm.shEPSS 0.55%via OSV
CVE-2025-69725Medium· 4.7
8mo ago

chi has an open redirect vulnerability in the RedirectSlashes middleware

chi has an open redirect vulnerability in the RedirectSlashes middleware

▾ Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.22%via OSV
CVE-2026-22772Medium· 5.8
8mo ago

Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

▾ Sunlitsigstore · github.com/sigstore/fulcioEPSS 0.24%via OSV
CVE-2026-22703Medium· 5.5
8mo ago

github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)

A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.11%via CSAF
CVE-2025-68151Medium
8mo ago

CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

▾ Sunlitcoredns · github.com/coredns/corednsEPSS 0.48%via OSV
CVE-2025-68939High· 8.2
9mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
CVE-2025-68383Medium· 6.5
9mo ago

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

▾ Sunlitelastic · github.com/elastic/beats/v7EPSS 0.19%via OSV
CVE-2025-63389Critical
9mo ago

Ollama Platform has missing authentication enabling attackers to perform model management operations

Ollama Platform has missing authentication enabling attackers to perform model management operations

▾ Midnightollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2025-66001High· 8.8
9mo ago

NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

▾ Twilightneuvector · github.com/neuvector/neuvectorEPSS 0.37%via OSV
CVE-2025-66491Medium· 5.9
9mo ago

Traefik Inverted TLS Verification Logic in ingress-nginx Provider

Traefik Inverted TLS Verification Logic in ingress-nginx Provider

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.22%via OSV
CVE-2025-66564High· 7.5
9mo ago

Sigstore Timestamp Authority allocates excessive memory during request parsing

Sigstore Timestamp Authority allocates excessive memory during request parsing

▾ Twilightsigstore · github.com/sigstore/timestamp-authorityEPSS 0.44%via OSV
CVE-2025-65637HighPoC
9mo ago

Logrus is vulnerable to DoS when using Entry.Writer()

Logrus is vulnerable to DoS when using Entry.Writer()

▾ Midnightsirupsen · github.com/sirupsen/logrusEPSS 0.63%via OSV
CVE-2025-10543Medium
10mo ago

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes

▾ Sunliteclipse · github.com/eclipse/paho.mqtt.golangEPSS 0.23%via OSV
CVE-2025-61729None
10mo ago

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

▾ Sunlitstdlib · stdlibEPSS 0.46%via OSV
CVE-2025-64715Medium· 4.0
10mo ago

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.17%via OSV
CVE-2025-65965High
10mo ago

Grype has a credential disclosure vulnerability in its JSON output

Grype has a credential disclosure vulnerability in its JSON output

▾ Twilightanchore · github.com/anchore/grypeEPSS 0.15%via OSV
CVE-2025-65942Low· 2.7
10mo ago

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

▾ SunlitVictoriaMetrics · github.com/VictoriaMetrics/VictoriaMetricsEPSS 0.34%via OSV
CVE-2025-64761High
10mo ago

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.36%via OSV
CVE-2025-64751Medium
10mo ago

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.29%via OSV
CVE-2025-47913High· 7.5
10mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.6)EPSS 0.62%via CSAF
CVE-2025-64324High· 7.7
10mo ago

KubeVirt Vulnerable to Arbitrary Host File Read and Write

KubeVirt Vulnerable to Arbitrary Host File Read and Write

▾ Twilightkubevirt · kubevirt.io/kubevirtEPSS 0.22%via OSV
CVE-2025-64436Medium· 5.3
10mo ago

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.26%via OSV
CVE-2025-64437Medium· 5.0
10mo ago

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.21%via OSV
CVE-2025-58188Medium
11mo ago

crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)

A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via CSAF
CVE-2025-58183None
11mo ago

Unbounded allocation when parsing GNU sparse map in archive/tar

Unbounded allocation when parsing GNU sparse map in archive/tar

▾ Sunlitstdlib · stdlibEPSS 0.41%via OSV
CVE-2025-11374Medium· 6.5
11mo ago

github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)

A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.40%via CSAF
CVEs tagged “go” — page 40 · VulnSea