VulnSea

Tagged “go”

CVEs tagged go, newest first.

1746 CVEsRSS

CVE-2022-23525High· 7.5⚖ disputed
3y ago

helm: Denial of service through through repository index file (CVE-2022-23525)

A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.14EPSS 0.86%via CSAF
CVE-2022-23469Low· 3.5
3y ago

Traefik may display authorization header in the debug logs

Traefik may display authorization header in the debug logs

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 1.0%via OSV
CVE-2022-46153Medium· 6.5
3y ago

Traefik routes exposed with an empty TLSOption

Traefik routes exposed with an empty TLSOption

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.51%via OSV
CVE-2022-23471Medium· 5.7
3y ago

containerd CRI stream server vulnerable to host memory exhaustion via terminal

containerd CRI stream server vulnerable to host memory exhaustion via terminal

▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 1.1%via OSV
CVE-2022-46146Medium· 6.2
3y ago

Prometheus Exporter-Toolkit is vulnerable to authentication bypass

Prometheus Exporter-Toolkit is vulnerable to authentication bypass

▾ Sunlitprometheus · github.com/prometheus/exporter-toolkitEPSS 1.2%via OSV
CVE-2022-3920High· 7.5
3y ago

Missing Authorization in HashiCorp Consul

Missing Authorization in HashiCorp Consul

▾ Twilighthashicorp · github.com/hashicorp/consulEPSS 0.70%via OSV
CVE-2022-39307Medium· 5.3
3y ago

grafana: User enumeration via forget password (CVE-2022-39307)

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via CSAF
CVE-2022-39306High· 8.1
3y ago

grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)

An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.76%via CSAF
CVE-2022-3023Critical· 9.8
3y ago

TiDB vulnerable to Use of Externally-Controlled Format String

TiDB vulnerable to Use of Externally-Controlled Format String

▾ Midnightpingcap · github.com/pingcap/tidbEPSS 0.61%via OSV
CVE-2022-3616Medium· 5.4
3y ago

OctoRPKI crashes when max iterations is reached

OctoRPKI crashes when max iterations is reached

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.43%via OSV
CVE-2022-31683Medium· 5.4
3y ago

Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution

Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution

▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.45%via OSV
CVE-2022-32149High· 7.5
3y ago

golang.org/x/text/language Denial of service via crafted Accept-Language header

golang.org/x/text/language Denial of service via crafted Accept-Language header

▾ Twilightx · golang.org/x/textEPSS 1.5%via OSV
CVE-2021-21271Medium· 6.5
3y ago

Tendermint Core vulnerable to Uncontrolled Resource Consumption

Tendermint Core vulnerable to Uncontrolled Resource Consumption

▾ Sunlittendermint · github.com/tendermint/tendermintEPSS 1.7%via OSV
CVE-2020-7711High· 7.5
3y ago

goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

goxmldsig vulnerable to crash on nil-pointer dereference caused by sending malformed XML signatures

▾ Twilightrussellhaering · github.com/russellhaering/goxmldsigEPSS 1.8%via OSV
CVE-2020-15115Medium· 5.8
3y ago

etcd has no minimum password length

etcd has no minimum password length

▾ Sunlitetcd · go.etcd.io/etcd/client/v3EPSS 1.3%via OSV
CVE-2022-41715None
3y ago

Memory exhaustion when compiling regular expressions in regexp/syntax

Memory exhaustion when compiling regular expressions in regexp/syntax

▾ Sunlitstdlib · stdlibEPSS 1.4%via OSV
CVE-2022-2880None
3y ago

Incorrect sanitization of forwarded query parameters in net/http/httputil

Incorrect sanitization of forwarded query parameters in net/http/httputil

▾ Sunlitstdlib · stdlibEPSS 1.2%via OSV
CVE-2022-2879None
3y ago

Unbounded memory consumption when reading headers in archive/tar

Unbounded memory consumption when reading headers in archive/tar

▾ Sunlitstdlib · stdlibEPSS 1.7%via OSV
CVE-2020-15106Medium· 5.3
3y ago

etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

▾ Sunlitetcd · go.etcd.io/etcd/v3EPSS 1.3%via OSV
CVE-2022-2529High· 7.5
3y ago

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

▾ Twilightcloudflare · github.com/cloudflare/goflow/v3EPSS 0.87%via OSV
CVE-2021-41803High· 7.1
4y ago

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

▾ Twilighthashicorp · github.com/hashicorp/consulEPSS 1.1%via OSV
CVE-2021-36782Critical· 9.9PoC
4y ago

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

▾ Abyssalrancher · github.com/rancher/rancherEPSS 4.2%via OSV
GHSA-qv98-3369-g364High
4y ago

KubeVirt vulnerable to arbitrary file read on host

KubeVirt vulnerable to arbitrary file read on host

▾ Twilightkubevirt · kubevirt.io/kubevirtvia OSV
CVE-2022-32190None
4y ago

Failure to strip relative path components in net/url

Failure to strip relative path components in net/url

▾ Sunlitstdlib · stdlibEPSS 2.2%via OSV
CVE-2022-27664High· 7.5
4y ago

golang.org/x/net/http2 Denial of Service vulnerability

golang.org/x/net/http2 Denial of Service vulnerability

▾ Twilightx · golang.org/x/netEPSS 3.3%via OSV
GO-2022-0965None
4y ago

Unbounded recursion in JSON parsing in k8s.io/apimachinery

Unbounded recursion in JSON parsing in k8s.io/apimachinery

▾ Sunlitapimachinery · k8s.io/apimachineryvia OSV
CVE-2022-31677Medium· 4.9
4y ago

Pinniped Supervisor Insufficient Session Expiration vulnerability

Pinniped Supervisor Insufficient Session Expiration vulnerability

▾ Sunlitgo.pinniped.dev · go.pinniped.devEPSS 0.45%via OSV
CVE-2022-36055Medium· 6.5
4y ago

Helm Vulnerable to denial of service through string value parsing

Helm Vulnerable to denial of service through string value parsing

▾ Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
CVE-2022-3064High· 7.5
4y ago

go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)

A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 1.7%via CSAF
CVE-2022-36633High· 8.8PoC
4y ago

Improper token validation leading to code execution in Teleport

Improper token validation leading to code execution in Teleport

▾ Midnightgravitational · github.com/gravitational/teleportEPSS 50%via OSV
CVEs tagged “go” — page 53 · VulnSea