VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2024-31990Medium· 4.8
2y ago

Argo CD's API server does not enforce project sourceNamespaces

Argo CD's API server does not enforce project sourceNamespaces

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.45%via OSV
CVE-2024-28869High· 7.5
2y ago

traefik: denial of service (CVE-2024-28869)

An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default …

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 1.0%via CSAF
CVE-2024-29902Medium· 4.2
2y ago

Cosign malicious attachments can cause system-wide denial of service

Cosign malicious attachments can cause system-wide denial of service

▾ Sunlitsigstore · github.com/sigstore/cosignEPSS 0.66%via OSV
CVE-2024-32644Critical· 9.1
2y ago

Evmos transaction execution not accounting for all state transition after interaction with precompiles

Evmos transaction execution not accounting for all state transition after interaction with precompiles

▾ Midnightevmos · github.com/evmos/evmos/v16EPSS 0.94%via OSV
CVE-2024-28224High· 8.8
2y ago

Ollama DNS rebinding vulnerability

Ollama DNS rebinding vulnerability

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.35%via OSV
CVE-2024-3250Medium· 6.5
2y ago

Pebble service manager's file pull API allows access by any user

Pebble service manager's file pull API allows access by any user

▾ Sunlitcanonical · github.com/canonical/pebbleEPSS 0.20%via OSV
CVE-2023-45288Medium· 5.3PoC
2y ago

net/http, x/net/http2: close connections when receiving too many headers

net/http, x/net/http2: close connections when receiving too many headers

▾ Twilightnet · net/httpEPSS 92%via OSV
CVE-2024-29893Medium· 6.5
2y ago

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.97%via OSV
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2024-1394High· 7.5
2y ago

Memory leaks in code encrypting and verifying RSA payloads

Memory leaks in code encrypting and verifying RSA payloads

▾ Twilightgolang-fips · github.com/golang-fips/goEPSS 1.5%via OSV
CVE-2024-1753High· 8.6PoC
2y ago

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…

▾ MidnightRed Hat · buildahEPSS 0.49%via NVD
CVE-2024-21661High· 7.5
2y ago

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

▾ Twilightargoproj · github.com/argoproj/argo-cdEPSS 1.2%via OSV
CVE-2024-28248High· 7.2
2y ago

Intermittent HTTP policy bypass

Intermittent HTTP policy bypass

▾ Twilightcilium · github.com/cilium/ciliumEPSS 0.62%via OSV
CVE-2024-21652Medium· 5.4
2y ago

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.75%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2023-50726Medium· 6.4
2y ago

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.53%via OSV
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2024-27304High· 8.1PoC
2y ago

pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…

▾ MidnightRed Hat · RHACS 4.3 for RHEL 8EPSS 1.1%via CSAF
CVE-2024-28110High· 7.5
2y ago

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

▾ Twilightcloudevents · github.com/cloudevents/sdk-go/v2EPSS 0.66%via OSV
CVE-2024-27288Medium· 6.3
2y ago

1Panel open source panel project has an unauthorized vulnerability.

1Panel open source panel project has an unauthorized vulnerability.

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 0.47%via OSV
CVE-2024-27918High· 8.2
2y ago

Coder's OIDC authentication allows email with partially matching domain to register

Coder's OIDC authentication allows email with partially matching domain to register

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.97%via OSV
CVE-2023-50658Medium· 5.3
2y ago

jose2go vulnerable to denial of service via large p2c value

jose2go vulnerable to denial of service via large p2c value

▾ Sunlitdvsekhvalnov · github.com/dvsekhvalnov/jose2goEPSS 0.82%via OSV
CVE-2024-1949Low· 2.6
2y ago

Mattermost race condition

Mattermost race condition

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.27%via OSV
CVE-2024-1952Low· 3.1
2y ago

Mattermost incorrectly allows access individual posts

Mattermost incorrectly allows access individual posts

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.37%via OSV
CVE-2024-23493Medium· 4.3
2y ago

Mattermost leaks details of AD/LDAP groups of a teams

Mattermost leaks details of AD/LDAP groups of a teams

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.39%via OSV
CVE-2024-24988Medium· 4.3
2y ago

Mattermost denial of service through long emoji value

Mattermost denial of service through long emoji value

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.68%via OSV
CVE-2024-25630Medium· 6.1
2y ago

Unencrypted ingress/health traffic when using Wireguard transparent encryption

Unencrypted ingress/health traffic when using Wireguard transparent encryption

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.18%via OSV
CVE-2024-1485High· 8.0
2y ago

registry-support: decompress can delete files outside scope via relative paths

registry-support: decompress can delete files outside scope via relative paths

▾ Twilightdevfile · github.com/devfile/registry-support/registry-libraryEPSS 0.94%via OSV
CVE-2023-6152Medium· 5.4
2y ago

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.4%via OSV
CVE-2024-1402Medium· 4.3
2y ago

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost vulnerable to denial of service via large number of emoji reactions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.52%via OSV
CVEs tagged “go” — page 47 · VulnSea