Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-23831Medium· 5.3github.com/sigstore/rekor: Rekor denial of service (CVE-2026-23831)
Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Ca…
CVE-2026-23991Medium· 5.9github.com/theupdateframework/go-tuf/v2: go-tuf client DoS via malformed server response (CVE-2026-23991)
A denial of service flaw has been discovered in go-tuf. If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial o…
CVE-2026-23990Medium· 5.3Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims
Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims
CVE-2026-23849Medium· 5.3File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
CVE-2026-23644Highesm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages
CVE-2025-69725Medium· 4.7chi has an open redirect vulnerability in the RedirectSlashes middleware
chi has an open redirect vulnerability in the RedirectSlashes middleware
CVE-2026-22772Medium· 5.8Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
CVE-2026-22703Medium· 5.5github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)
A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…
CVE-2025-68151MediumCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2025-68939High· 8.2Gitea allows attackers to add attachments with forbidden file extensions
Gitea allows attackers to add attachments with forbidden file extensions
CVE-2025-68383Medium· 6.5Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
Ollama Platform has missing authentication enabling attackers to perform model management operations
CVE-2025-66001High· 8.8NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
CVE-2025-66491Medium· 5.9Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
CVE-2025-66564High· 7.5Sigstore Timestamp Authority allocates excessive memory during request parsing
Sigstore Timestamp Authority allocates excessive memory during request parsing
CVE-2025-65637HighPoCLogrus is vulnerable to DoS when using Entry.Writer()
Logrus is vulnerable to DoS when using Entry.Writer()
CVE-2025-10543MediumEclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
CVE-2025-61729NoneExcessive resource consumption when printing error string for host certificate validation in crypto/x509
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-64715Medium· 4.0Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
CVE-2025-65965HighGrype has a credential disclosure vulnerability in its JSON output
Grype has a credential disclosure vulnerability in its JSON output
CVE-2025-65942Low· 2.7VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
CVE-2025-64761HighOpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
CVE-2025-47913High· 7.5golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)
A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…
CVE-2025-64324High· 7.7KubeVirt Vulnerable to Arbitrary Host File Read and Write
KubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-64436Medium· 5.3KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-64437Medium· 5.0KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
CVE-2025-58188Mediumcrypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)
A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…
CVE-2025-58183NoneUnbounded allocation when parsing GNU sparse map in archive/tar
Unbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-11374Medium· 6.5github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)
A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.