Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2025-3445High· 8.1mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
CVE-2025-32093Medium· 4.7Mattermost Fails to Restrict Certain Operations on System Admins
Mattermost Fails to Restrict Certain Operations on System Admins
CVE-2025-1386MediumCVE-2025-1386- Query smuggling in ch-go library
CVE-2025-1386- Query smuggling in ch-go library
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2025-31489HighPoCMinIO performs incomplete signature validation for unsigned-trailer uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
CVE-2023-27591High· 7.5Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
CVE-2025-30223Critical· 9.3Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
CVE-2025-30204NoneExcessive memory allocation during header parsing in github.com/golang-jwt/jwt
Excessive memory allocation during header parsing in github.com/golang-jwt/jwt
CVE-2025-1097High· 8.8PoCngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
CVE-2025-24513Medium· 4.8ingress-nginx controller - auth secret file path traversal vulnerability
ingress-nginx controller - auth secret file path traversal vulnerability
CVE-2025-29778Medium· 5.8Kyverno ignores subjectRegExp and IssuerRegExp
Kyverno ignores subjectRegExp and IssuerRegExp
CVE-2025-30162Low· 3.2Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
CVE-2025-45286LowReflected XSS in go-httpbin due to unrestricted client control over Content-Type
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
Ollama Divide by Zero Vulnerability
CVE-2024-7598Low· 3.1Kubernetes kube-apiserver Vulnerable to Race Condition
Kubernetes kube-apiserver Vulnerable to Race Condition
CVE-2024-40635Medium· 4.6PoCcontainerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)
A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2025-25279Critical· 9.9PoCMattermost allows reading arbitrary files related to importing boards
Mattermost allows reading arbitrary files related to importing boards
CVE-2025-22866Medium· 5.3crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…
CVE-2025-26260Medium· 6.5Plenti - Code Injection - Denial of Services
Plenti - Code Injection - Denial of Services
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
GHSA-274v-mgcv-cm8jMedium· 6.8Argo CD GitOps Engine does not scrub secret values from patch errors
Argo CD GitOps Engine does not scrub secret values from patch errors
CVE-2024-45339High· 7.1Insecure Temporary File usage in github.com/golang/glog
Insecure Temporary File usage in github.com/golang/glog
CVE-2024-11218High· 8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …
CVE-2024-5138Medium· 4.0CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-5138: snapd snapctl auth bypass
CVE-2025-20086Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-20088Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props