Tagged “go”
CVEs tagged go, newest first.
1735 CVEsRSS
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
Rancher UI has Stored Cross-site Scripting vulnerability
CVE-2024-56138Medium· 4.0notation-go's timestamp signature generation lacks certificate revocation check
notation-go's timestamp signature generation lacks certificate revocation check
CVE-2024-56323MediumOpenFGA Authorization Bypass
OpenFGA Authorization Bypass
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2025-20033Medium· 4.3Mattermost Improper Validation of Specified Type of Input vulnerability
Mattermost Improper Validation of Specified Type of Input vulnerability
CVE-2025-21613NoneArgument Injection via the URL field in github.com/go-git/go-git
Argument Injection via the URL field in github.com/go-git/go-git
GHSA-32gq-x56h-299cMediumage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
CVE-2024-45337NonePoCMisuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
CVE-2024-54132MediumDownloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
CVE-2024-53257Medium· 4.9Vitess allows HTML injection in /debug/querylogz & /debug/env
Vitess allows HTML injection in /debug/querylogz & /debug/env
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
Moby Race Condition vulnerability
CVE-2024-53859Medium· 6.5`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
CVE-2024-10220High· 8.1PoCKubernetes kubelet arbitrary command execution
Kubernetes kubelet arbitrary command execution
GHSA-p7mv-53f2-4cwjHighCometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CVE-2024-51744Low· 3.1golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…
A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-10006High· 8.3hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)
A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
Mattermost Server allows user to get private channel names
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org
Grafana org admin can delete pending invites in different org
GO-2024-3219Nonegithub.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
GHSA-7h65-4p22-39j6Critical· 9.8github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
CVE-2024-47825Medium· 4.0Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-9675High· 7.8⚖ disputedA vulnerability was found in Buildah
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…
CVE-2024-47534High· 7.5Incorrect delegation lookups can make go-tuf download the wrong artifact
Incorrect delegation lookups can make go-tuf download the wrong artifact
CVE-2024-9355Medium· 6.5A vulnerability was found in Golang FIPS OpenSSL
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…
CVE-2024-47003Medium· 5.4Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events