Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2025-62705MediumOpenBao and Vault Leak []byte Fields in Audit Logs
OpenBao and Vault Leak []byte Fields in Audit Logs
CVE-2025-62513MediumOpenBao leaks HTTPRawBody in Audit Logs
OpenBao leaks HTTPRawBody in Audit Logs
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-62375Mediumgo-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
CVE-2025-11579Medium· 5.3PoCgithub.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)
A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…
CVE-2025-59530Medium· 5.3⚖ disputedgithub.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)
A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …
CVE-2025-54287Medium· 6.5Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
CVE-2025-54286High· 8.3Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
CVE-2025-54288Medium· 4.1Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
CVE-2025-54293Medium· 6.5Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
CVE-2025-54289Medium· 6.8Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
CVE-2025-55191Medium· 4.3⚖ disputedgithub.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)
A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…
CVE-2025-47906Medium· 6.5os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)
A path handling flaw has been discovered in the os/exec go package. If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result i…
CVE-2025-59341HighPoCesm.sh has File Inclusion issue
esm.sh has File Inclusion issue
CVE-2025-9566High· 8.1There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…
CVE-2025-55190High· 8.8PoCgithub.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)
An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.
CVE-2025-47909Mediumgithub.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2025-54996High· 7.2OpenBao Root Namespace Operator May Elevate Token Privileges
OpenBao Root Namespace Operator May Elevate Token Privileges
CVE-2025-55003Medium· 5.7OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
CVE-2025-54998Medium· 5.3OpenBao Userpass and LDAP User Lockout Bypass
OpenBao Userpass and LDAP User Lockout Bypass
CVE-2025-54999Low· 3.7OpenBao has a Timing Side-Channel in the Userpass Auth Method
OpenBao has a Timing Side-Channel in the Userpass Auth Method
CVE-2025-55000Medium· 6.5OpenBao TOTP Secrets Engine Code Reuse
OpenBao TOTP Secrets Engine Code Reuse
CVE-2025-55001Medium· 6.5OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2025-54576High· 7.4github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)
An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …
CVE-2021-21411Medium· 5.5OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0