Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2024-31990Medium· 4.8Argo CD's API server does not enforce project sourceNamespaces
Argo CD's API server does not enforce project sourceNamespaces
CVE-2024-28869High· 7.5traefik: denial of service (CVE-2024-28869)
An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default …
CVE-2024-29902Medium· 4.2Cosign malicious attachments can cause system-wide denial of service
Cosign malicious attachments can cause system-wide denial of service
CVE-2024-32644Critical· 9.1Evmos transaction execution not accounting for all state transition after interaction with precompiles
Evmos transaction execution not accounting for all state transition after interaction with precompiles
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
Ollama DNS rebinding vulnerability
CVE-2024-3250Medium· 6.5Pebble service manager's file pull API allows access by any user
Pebble service manager's file pull API allows access by any user
CVE-2023-45288Medium· 5.3PoCnet/http, x/net/http2: close connections when receiving too many headers
net/http, x/net/http2: close connections when receiving too many headers
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…
CVE-2024-1394High· 7.5Memory leaks in code encrypting and verifying RSA payloads
Memory leaks in code encrypting and verifying RSA payloads
CVE-2024-1753High· 8.6PoCA flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
Intermittent HTTP policy bypass
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component
Cross-site scripting on application summary component
CVE-2023-50726Medium· 6.4Users with `create` but not `override` privileges can perform local sync
Users with `create` but not `override` privileges can perform local sync
CVE-2024-1442Medium· 6.0grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)
A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…
CVE-2024-27304High· 8.1PoCpgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…
CVE-2024-28110High· 7.5Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials
Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials
CVE-2024-27288Medium· 6.31Panel open source panel project has an unauthorized vulnerability.
1Panel open source panel project has an unauthorized vulnerability.
CVE-2024-27918High· 8.2Coder's OIDC authentication allows email with partially matching domain to register
Coder's OIDC authentication allows email with partially matching domain to register
CVE-2023-50658Medium· 5.3jose2go vulnerable to denial of service via large p2c value
jose2go vulnerable to denial of service via large p2c value
CVE-2024-1949Low· 2.6Mattermost race condition
Mattermost race condition
CVE-2024-1952Low· 3.1Mattermost incorrectly allows access individual posts
Mattermost incorrectly allows access individual posts
CVE-2024-23493Medium· 4.3Mattermost leaks details of AD/LDAP groups of a teams
Mattermost leaks details of AD/LDAP groups of a teams
CVE-2024-24988Medium· 4.3Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2024-1485High· 8.0registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
CVE-2023-6152Medium· 5.4Email Validation Bypass And Preventing Sign Up From Email's Owner
Email Validation Bypass And Preventing Sign Up From Email's Owner
CVE-2024-1402Medium· 4.3Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost vulnerable to denial of service via large number of emoji reactions