VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2025-3445High· 8.1
1y ago

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

▾ Twilightmholt · github.com/mholt/archiverEPSS 0.50%via OSV
CVE-2025-2475Medium· 5.4
1y ago

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.23%via OSV
CVE-2025-32093Medium· 4.7
1y ago

Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost Fails to Restrict Certain Operations on System Admins

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2025-1386Medium
1y ago

CVE-2025-1386- Query smuggling in ch-go library

CVE-2025-1386- Query smuggling in ch-go library

▾ SunlitClickHouse · github.com/ClickHouse/ch-goEPSS 0.38%via OSV
CVE-2025-32387Medium· 6.5
1y ago

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.48%via OSV
CVE-2025-32386Medium· 6.5
1y ago

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.45%via OSV
CVE-2025-31489HighPoC
1y ago

MinIO performs incomplete signature validation for unsigned-trailer uploads

MinIO performs incomplete signature validation for unsigned-trailer uploads

▾ Midnightminio · github.com/minio/minioEPSS 2.4%via OSV
CVE-2023-27591High· 7.5
1y ago

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

▾ Twilightv2 · miniflux.app/v2EPSS 0.76%via OSV
CVE-2025-30223Critical· 9.3
1y ago

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

▾ Midnightbeego · github.com/beego/beego/v2EPSS 0.59%via OSV
CVE-2025-30204None
1y ago

Excessive memory allocation during header parsing in github.com/golang-jwt/jwt

Excessive memory allocation during header parsing in github.com/golang-jwt/jwt

▾ Sunlitgolang-jwt · github.com/golang-jwt/jwtEPSS 0.74%via OSV
CVE-2025-1097High· 8.8PoC
1y ago

ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 33%via OSV
CVE-2025-24513Medium· 4.8
1y ago

ingress-nginx controller - auth secret file path traversal vulnerability

ingress-nginx controller - auth secret file path traversal vulnerability

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 3.3%via OSV
CVE-2025-29778Medium· 5.8
1y ago

Kyverno ignores subjectRegExp and IssuerRegExp

Kyverno ignores subjectRegExp and IssuerRegExp

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.34%via OSV
CVE-2025-30162Low· 3.2
1y ago

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.22%via OSV
CVE-2025-45286Low
1y ago

Reflected XSS in go-httpbin due to unrestricted client control over Content-Type

Reflected XSS in go-httpbin due to unrestricted client control over Content-Type

▾ Sunlitmccutchen · github.com/mccutchen/go-httpbinEPSS 0.27%via OSV
CVE-2024-8063High· 7.5
1y ago

Ollama Divide by Zero Vulnerability

Ollama Divide by Zero Vulnerability

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.63%via OSV
CVE-2024-7598Low· 3.1
1y ago

Kubernetes kube-apiserver Vulnerable to Race Condition

Kubernetes kube-apiserver Vulnerable to Race Condition

▾ Sunlitkubernetes · k8s.io/kubernetes/cmd/kube-apiserverEPSS 0.31%via OSV
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.29%via CSAF
CVE-2025-1767Medium· 6.5
1y ago

Kubernetes GitRepo Volume Inadvertent Local Repository Access

Kubernetes GitRepo Volume Inadvertent Local Repository Access

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.55%via OSV
CVE-2025-23387Medium· 5.3
1y ago

Rancher's SAML-based login via CLI can be denied by unauthenticated users

Rancher's SAML-based login via CLI can be denied by unauthenticated users

▾ Sunlitrancher · github.com/rancher/rancherEPSS 0.58%via OSV
CVE-2025-25279Critical· 9.9PoC
1y ago

Mattermost allows reading arbitrary files related to importing boards

Mattermost allows reading arbitrary files related to importing boards

▾ Abyssalmattermost · github.com/mattermost/mattermost/server/v8EPSS 24%via OSV
CVE-2025-22866Medium· 5.3
1y ago

crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)

A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.29%via CSAF
CVE-2025-26260Medium· 6.5
1y ago

Plenti - Code Injection - Denial of Services

Plenti - Code Injection - Denial of Services

▾ Sunlitplentico · github.com/plentico/plentiEPSS 0.76%via OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
GHSA-274v-mgcv-cm8jMedium· 6.8
1y ago

Argo CD GitOps Engine does not scrub secret values from patch errors

Argo CD GitOps Engine does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/gitops-enginevia OSV
CVE-2024-45339High· 7.1
1y ago

Insecure Temporary File usage in github.com/golang/glog

Insecure Temporary File usage in github.com/golang/glog

▾ Twilightgolang · github.com/golang/glogEPSS 0.32%via OSV
CVE-2024-11218High· 8.6
1y ago

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …

▾ Twilightcontainers · github.com/containers/buildahEPSS 0.36%via NVD
CVE-2024-5138Medium· 4.0
1y ago

CVE-2024-5138: snapd snapctl auth bypass

CVE-2024-5138: snapd snapctl auth bypass

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.83%via OSV
CVE-2025-20086Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.43%via OSV
CVE-2025-20088Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.56%via OSV
CVEs tagged “go” — page 43 · VulnSea