VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2026-88046Medium· 5.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk…

▾ Sunlitrclone · rcloneEPSS 0.37%via NVD
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVE-2026-88017High· 7.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…

▾ Twilightrclone · rcloneEPSS 0.43%via NVD
CVE-2026-88012Medium· 5.3
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…

▾ Sunlittraefik · traefikEPSS 0.52%via NVD
CVE-2026-88044Critical· 9.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.56%via NVD
CVE-2026-88015Medium· 5.3PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

▾ Twilightrclone · rcloneEPSS 0.51%via NVD
CVE-2026-88013Low· 3.7PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88045High· 7.5PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

▾ Midnightrclone · rcloneEPSS 0.63%via NVD
CVE-2026-88016High· 7.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

▾ Midnightrclone · rcloneEPSS 0.27%via NVD
CVE-2026-88009High· 8.2
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…

▾ Twilighttraefik · traefikEPSS 0.44%via NVD
CVE-2026-88004High· 7.4
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…

▾ Twilighttraefik · traefikEPSS 0.45%via NVD
CVE-2026-88014Medium· 6.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…

▾ Sunlitrclone · rcloneEPSS 0.20%via NVD
CVE-2026-88008Critical· 9.1⚖ disputed
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

▾ Midnighttraefik · traefikEPSS 0.49%via NVD
CVE-2026-88011High· 8.1⚖ disputed
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …

▾ Twilighttraefik · traefikEPSS 0.42%via NVD
CVE-2026-88007Critical· 9.1
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
CVE-2026-49837Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…

▾ Sunlitosrg · gobgpEPSS 0.33%via NVD
CVE-2026-49838Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …

▾ Sunlitosrg · gobgpEPSS 0.41%via NVD
GO-2026-6302None
2w ago

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

▾ Sunlitcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
GHSA-hxjg-93wc-h8p8High· 8.8
2w ago

Komari: Management Interface CSRF

Komari: Management Interface CSRF

▾ Twilightkomari-monitor · github.com/komari-monitor/komarivia OSV
CVE-2026-59185High· 8.5
2w ago

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

▾ Twilightidentrail · github.com/identrail/identrailvia OSV
CVE-2026-59172High· 7.8
2w ago

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

▾ Twilightcandid82 · github.com/candid82/jokervia OSV
CVE-2025-24979Medium· 5.5
2w ago

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-24978Low· 3.7
2w ago

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-58363Medium· 5.5
2w ago

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
GHSA-57v5-wqx3-cgj4Medium· 5.8
2w ago

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia OSV
CVE-2026-72790Medium· 5.8
2w ago

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-63464High· 7.7PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…

▾ Midnightforgekeep · nebula-meshEPSS 0.46%via NVD
CVE-2026-72799Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-72798High· 8.6
3w ago

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-72796Medium· 5.8
3w ago

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.35%via GHSA
CVEs tagged “go” — page 6 · VulnSea