VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-56668High· 8.1
1w ago

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.41%via OSV
CVE-2026-76081Medium· 5.5
1w ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.40%via NVD
CVE-2026-65838High· 8.2
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

▾ Twilightzalando · skipperEPSS 0.46%via NVD
CVE-2026-53495Medium· 6.8
1w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

▾ Sunlitcontainerd · containerdEPSS 0.16%via NVD
CVE-2026-84445High· 8.7
1w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

▾ Twilightgrpc · grpc-goEPSS 0.64%via NVD
CVE-2026-57497Medium· 5.3
1w ago

webtransport-go is an implementation of the WebTransport protocol

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, …

▾ Sunlitquic-go · webtransport-goEPSS 0.52%via NVD
CVE-2026-54246Medium· 5.7
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…

▾ Sunlitzalando · skipperEPSS 0.34%via NVD
CVE-2026-54247Medium· 4.3
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …

▾ Sunlitzalando · skipperEPSS 0.30%via NVD
CVE-2026-53718Medium· 6.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…

▾ Sunlitenvoyproxy · gatewayEPSS 0.41%via NVD
CVE-2026-53716Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53719Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a n…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53717Medium· 6.5
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53715Medium· 5.3
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

▾ Sunlitenvoyproxy · gatewayEPSS 0.47%via NVD
CVE-2026-53713Critical· 9.1
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

▾ Midnightenvoyproxy · gatewayEPSS 0.43%via NVD
CVE-2026-53714High· 7.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-54452Medium· 6.3
1w ago

safeurl is a server-side request forgery protection library

safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIP…

▾ Sunlitdoyensec · safeurlEPSS 0.52%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-47253High· 7.3PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll wi…

▾ Midnightjulien040 · anyqueryEPSS 0.44%via NVD
CVE-2026-47701High· 7.7
1w ago

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor …

▾ Twilightopen-telemetry · opentelemetry-operatorEPSS 0.46%via NVD
CVE-2026-55866Low· 3.7
1w ago

SpiceDB is an open source database system for creating and managing security-critical application permissions

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or…

▾ Sunlitauthzed · spicedbEPSS 0.34%via NVD
CVE-2026-47256Medium· 5.3PoC
1w ago

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…

▾ Twilightopen-telemetry · opentelemetry-collector-contribEPSS 0.44%via NVD
CVE-2026-89090Medium· 5.9
2w ago

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

▾ SunlitAWS · AWS SDK for Go v2EPSS 0.30%via NVD
CVE-2026-56665Medium· 4.2
2w ago

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.27%via OSV
CVE-2026-50013High· 7.5
2w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…

▾ TwilightSpectoLabs · hoverflyEPSS 0.47%via NVD
CVE-2026-50018Medium· 6.5PoC
2w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

▾ TwilightSpectoLabs · hoverflyEPSS 0.54%via NVD
CVE-2026-54174High· 8.3
2w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

▾ Twilightchainguard-dev · melangeEPSS 0.15%via NVD
CVE-2026-54072Critical· 9.3PoC
2w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

▾ Abyssalauthorizerdev · authorizerEPSS 0.46%via NVD
CVE-2026-48496Medium· 6.2
2w ago

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…

▾ Sunlitopen-telemetry · opentelemetry-ebpf-profilerEPSS 0.18%via NVD
CVEs tagged “go” — page 5 · VulnSea