VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2024-52281High· 8.9
1y ago

Rancher UI has Stored Cross-site Scripting vulnerability

Rancher UI has Stored Cross-site Scripting vulnerability

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2024-56138Medium· 4.0
1y ago

notation-go's timestamp signature generation lacks certificate revocation check

notation-go's timestamp signature generation lacks certificate revocation check

▾ Sunlitnotaryproject · github.com/notaryproject/notation-goEPSS 0.13%via OSV
CVE-2024-56323Medium
1y ago

OpenFGA Authorization Bypass

OpenFGA Authorization Bypass

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.45%via OSV
CVE-2025-22445Low· 3.5
1y ago

Mattermost has Improper Check for Unusual or Exceptional Conditions

Mattermost has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.32%via OSV
CVE-2025-20033Medium· 4.3
1y ago

Mattermost Improper Validation of Specified Type of Input vulnerability

Mattermost Improper Validation of Specified Type of Input vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.62%via OSV
CVE-2025-21613None
1y ago

Argument Injection via the URL field in github.com/go-git/go-git

Argument Injection via the URL field in github.com/go-git/go-git

▾ Sunlitgo-git · github.com/go-git/go-git/v4EPSS 1.3%via OSV
GHSA-32gq-x56h-299cMedium
1y ago

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Sunlitage · filippo.io/agevia OSV
CVE-2024-45337NonePoC
1y ago

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

▾ Twilightx · golang.org/x/cryptoEPSS 3.2%via OSV
CVE-2024-54132Medium
1y ago

Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability

Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability

▾ Sunlitcli · github.com/cli/cli/v2EPSS 0.63%via OSV
CVE-2024-53257Medium· 4.9
1y ago

Vitess allows HTML injection in /debug/querylogz & /debug/env

Vitess allows HTML injection in /debug/querylogz & /debug/env

▾ Sunlitvitess · vitess.io/vitessEPSS 0.44%via OSV
CVE-2024-36621Medium· 6.5
1y ago

Moby Race Condition vulnerability

Moby Race Condition vulnerability

▾ Sunlitmoby · github.com/moby/mobyEPSS 0.63%via OSV
CVE-2024-53859Medium· 6.5
1y ago

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

▾ Sunlitcli · github.com/cli/go-gh/v2EPSS 0.53%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
GHSA-p7mv-53f2-4cwjHigh
1y ago

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

▾ Twilightcometbft · github.com/cometbft/cometbftvia OSV
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2024-8185High· 7.5
1y ago

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Hashicorp Vault vulnerable to denial of service through memory exhaustion

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.48%via OSV
CVE-2024-10006High· 8.3
1y ago

hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 0.47%via CSAF
CVE-2024-47401Medium· 4.3
1y ago

Mattermost Server vulnerable to application crash from attacker-generated large response

Mattermost Server vulnerable to application crash from attacker-generated large response

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.46%via OSV
CVE-2024-46872Medium· 4.6
1y ago

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.15%via OSV
CVE-2024-10241Medium· 4.3
1y ago

Mattermost Server allows user to get private channel names

Mattermost Server allows user to get private channel names

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.29%via OSV
CVE-2024-10452Low· 2.2
1y ago

Grafana org admin can delete pending invites in different org

Grafana org admin can delete pending invites in different org

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.49%via OSV
GO-2024-3219None
1y ago

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

▾ Sunlitcrossplane · github.com/crossplane/crossplanevia OSV
CVE-2023-32196Critical· 9.1
1y ago

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
GHSA-7h65-4p22-39j6Critical· 9.8
1y ago

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

▾ Midnightcrossplane · github.com/crossplane/crossplanevia OSV
CVE-2024-47825Medium· 4.0
1y ago

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.40%via OSV
CVE-2024-9180High· 7.2
1y ago

Vault Community Edition privilege escalation vulnerability

Vault Community Edition privilege escalation vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.53%via OSV
CVE-2024-9675High· 7.8⚖ disputed
1y ago

A vulnerability was found in Buildah

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…

▾ Twilightbuildah_project · buildahEPSS 0.39%via NVD
CVE-2024-47534High· 7.5
1y ago

Incorrect delegation lookups can make go-tuf download the wrong artifact

Incorrect delegation lookups can make go-tuf download the wrong artifact

▾ Twilighttheupdateframework · github.com/theupdateframework/go-tuf/v2EPSS 0.51%via OSV
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

▾ Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-47003Medium· 5.4
2y ago

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.58%via OSV
CVEs tagged “go” — page 44 · VulnSea