VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2025-62705Medium
11mo ago

OpenBao and Vault Leak []byte Fields in Audit Logs

OpenBao and Vault Leak []byte Fields in Audit Logs

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.33%via OSV
CVE-2025-62513Medium
11mo ago

OpenBao leaks HTTPRawBody in Audit Logs

OpenBao leaks HTTPRawBody in Audit Logs

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.32%via OSV
CVE-2025-59043High· 7.5
11mo ago

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.69%via OSV
CVE-2025-62375Medium
11mo ago

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

▾ Sunlitin-toto · github.com/in-toto/go-witnessEPSS 0.20%via OSV
CVE-2025-11579Medium· 5.3PoC
11mo ago

github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security 4EPSS 0.37%via CSAF
CVE-2025-59530Medium· 5.3⚖ disputed
11mo ago

github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)

A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.46%via CSAF
CVE-2025-54287Medium· 6.5
12mo ago

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

▾ Sunlitlxc · github.com/lxc/lxdEPSS 0.37%via OSV
CVE-2025-54286High· 8.3
12mo ago

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

▾ Twilightcanonical · github.com/canonical/lxdEPSS 0.13%via OSV
CVE-2025-54288Medium· 4.1
12mo ago

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.35%via OSV
CVE-2025-54293Medium· 6.5
12mo ago

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.58%via OSV
CVE-2025-54289Medium· 6.8
12mo ago

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.21%via OSV
CVE-2025-55191Medium· 4.3⚖ disputed
12mo ago

github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)

A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…

▾ SunlitRed Hat · Red Hat OpenShift GitOps 1.16EPSS 0.47%via CSAF
CVE-2025-47906Medium· 6.5
1y ago

os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)

A path handling flaw has been discovered in the os/exec go package. If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result i…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-59341HighPoC
1y ago

esm.sh has File Inclusion issue

esm.sh has File Inclusion issue

▾ Midnightesm-dev · github.com/esm-dev/esm.shEPSS 1.6%via OSV
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

▾ TwilightRed Hat · podmanEPSS 1.1%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

▾ MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.5%via CSAF
CVE-2025-47909Medium
1y ago

github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks

github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks

▾ Sunlitgorilla · github.com/gorilla/csrfEPSS 0.17%via OSV
CVE-2025-5187Medium· 6.7
1y ago

kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)

A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-54997Critical· 9.1
1y ago

Privileged OpenBao Operator May Execute Code on the Underlying Host

Privileged OpenBao Operator May Execute Code on the Underlying Host

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.38%via OSV
CVE-2025-54996High· 7.2
1y ago

OpenBao Root Namespace Operator May Elevate Token Privileges

OpenBao Root Namespace Operator May Elevate Token Privileges

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.31%via OSV
CVE-2025-55003Medium· 5.7
1y ago

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.24%via OSV
CVE-2025-54998Medium· 5.3
1y ago

OpenBao Userpass and LDAP User Lockout Bypass

OpenBao Userpass and LDAP User Lockout Bypass

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-54999Low· 3.7
1y ago

OpenBao has a Timing Side-Channel in the Userpass Auth Method

OpenBao has a Timing Side-Channel in the Userpass Auth Method

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.19%via OSV
CVE-2025-55000Medium· 6.5
1y ago

OpenBao TOTP Secrets Engine Code Reuse

OpenBao TOTP Secrets Engine Code Reuse

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-55001Medium· 6.5
1y ago

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.22%via OSV
CVE-2025-6013Medium· 6.5
1y ago

HashiCorp Vault ldap auth method may not have correctly enforced MFA

HashiCorp Vault ldap auth method may not have correctly enforced MFA

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.50%via OSV
CVE-2025-5999High· 7.2
1y ago

Hashicorp Vault has Privilege Escalation Vulnerability

Hashicorp Vault has Privilege Escalation Vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.51%via OSV
CVE-2025-6037Medium· 6.8
1y ago

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.25%via OSV
CVE-2025-54576High· 7.4
1y ago

github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …

▾ TwilightRed Hat · Red Hat Ceph Storage 8EPSS 1.2%via CSAF
CVE-2021-21411Medium· 5.5
1y ago

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.99%via OSV
CVEs tagged “go” — page 41 · VulnSea