Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
CVE-2025-22868High· 7.5golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
CVE-2025-54059Medium· 4.4melange's world-writable permissions expose SBOM files to potential image tampering
melange's world-writable permissions expose SBOM files to potential image tampering
CVE-2025-3415Medium· 4.3PoCGrafana's insecure DingDing Alert integration exposes sensitive information
Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2025-53893HighFile Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
CVE-2025-53826HighFile Browser’s insecure JWT handling can lead to session replay attacks after logout
File Browser’s insecure JWT handling can lead to session replay attacks after logout
CVE-2025-7453Low· 3.7ZPan Uses Hard-Coded Password
ZPan Uses Hard-Coded Password
CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint
Juju zip slip vulnerability via authenticated endpoint
CVE-2025-53547High· 8.5PoChelm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…
CVE-2025-52996Low· 3.1File Browser's password protection of links is bypassable
File Browser's password protection of links is bypassable
CVE-2025-52894MediumOpenBao allows cancellation of root rekey and recovery rekey operations without authentication
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
CVE-2025-52893Medium· 4.5OpenBao Inserts Sensitive Information into Log File when processing malformed data
OpenBao Inserts Sensitive Information into Log File when processing malformed data
CVE-2025-6032High· 8.3A flaw was found in Podman
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVE-2024-44905Medium· 6.5go-pg SQL injection vulnerability via the component /types/append_value.go
go-pg SQL injection vulnerability via the component /types/append_value.go
CVE-2025-22874High· 7.5crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)
A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.
CVE-2025-8556Low· 3.7CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CVE-2025-3260High· 8.3Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
CVE-2025-1792Low· 3.1Mattermost fails to properly enforce access controls for guest users
Mattermost fails to properly enforce access controls for guest users
CVE-2025-3611Low· 3.1Mattermost fails to properly enforce access control restrictions for System Manager roles
Mattermost fails to properly enforce access control restrictions for System Manager roles
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
CVE-2025-4166Medium· 4.5Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-46569HighOPA server Data API HTTP path injection of Rego
OPA server Data API HTTP path injection of Rego
CVE-2025-46327Low· 3.3Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
CVE-2025-46599Medium· 6.8CNCF K3s Kubernetes kubelet configuration exposes credentials
CNCF K3s Kubernetes kubelet configuration exposes credentials
CVE-2025-35965Medium· 6.5Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen
GoBGP panics due to a zero value for softwareVersionLen
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
GHSA-3wqc-mwfx-672pHigh· 7.5Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
CVE-2025-27936Medium· 5.3Mattermost vulnerable to Observable Timing Discrepancy
Mattermost vulnerable to Observable Timing Discrepancy