VulnSea

Tagged “go”

CVEs tagged go, newest first.

1732 CVEsRSS

CVE-2026-55678Medium
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…

▾ Sunlitbasekick-labs · github.com/basekick-labs/arcEPSS 0.66%via NVD
CVE-2026-56854Medium· 6.8
1mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)

A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.44%via CSAF
CVE-2026-55245High
1mo ago

Bifrost is an enterprise AI gateway for routing requests to model providers

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, clas…

▾ Twilightmaximhq · github.com/maximhq/bifrost/coreEPSS 0.61%via NVD
CVE-2026-55484High· 7.5
1mo ago

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning wi…

▾ Twilightguno1928 · github.com/guno1928/alos-httpEPSS 0.49%via NVD
CVE-2026-54754Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.43%via NVD
CVE-2026-54755Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.56%via NVD
CVE-2026-55569Medium· 6.6
1mo ago

aqua is a declarative command-line version manager written in Go

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains un…

▾ Sunlitaquaproj · github.com/aquaproj/aqua/v2EPSS 0.18%via NVD
CVE-2026-55834Medium· 4.3
1mo ago

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.37%via NVD
CVE-2026-54766Medium
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplica…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.43%via NVD
CVE-2026-55064Medium· 4.3
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55065High· 8.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.50%via NVD
CVE-2026-55066High· 7.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55067Medium· 5.0
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/model…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.34%via NVD
CVE-2026-55068Critical
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…

▾ Midnightfree5gc · github.com/free5gc/free5gcEPSS 0.59%via NVD
CVE-2026-54746Medium· 6.4
1mo ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…

▾ Sunlithatchet-dev · github.com/hatchet-dev/hatchetEPSS 0.37%via NVD
CVE-2026-55108High· 8.5
1mo ago

KubeVela is an open source application delivery platform

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, G…

▾ Twilightoam-dev · github.com/oam-dev/kubevelaEPSS 0.75%via NVD
CVE-2026-42350Low
1mo ago

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

▾ Sunlitakuity · github.com/akuity/kargoEPSS 0.41%via GHSA
GHSA-mf7q-r4rv-jv94High
1mo ago

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

▾ Twilightcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
1mo ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

▾ HadalGitea · GiteaEPSS 24%via CVEORG
CVE-2026-79921High· 7.5
1mo ago

amqp091-go is a Go AMQP 0.9.1 client

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead …

▾ Twilightrabbitmq · github.com/rabbitmq/amqp091-goEPSS 0.55%via NVD
CVE-2026-54563High· 7.1
1mo ago

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.32%via GHSA
CVE-2026-54523Critical· 9.6
1mo ago

Kyverno is a policy engine designed for cloud native platform engineering teams

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …

▾ Midnightkyverno · github.com/kyverno/kyvernoEPSS 0.47%via NVD
CVE-2026-54245High
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…

▾ Twilightfleetdm · github.com/fleetdm/fleetEPSS 0.57%via NVD
CVE-2026-48786Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.44%via NVD
CVE-2026-46370Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-46371Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-41262Medium· 4.3
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.30%via NVD
CVE-2026-55588Medium· 6.5⚖ disputed
1mo ago

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registr…

▾ Sunlitoras · oras.land/orasEPSS 0.54%via NVD
CVE-2026-79669Medium· 4.3
1mo ago

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access historical logs and real-time log streams via GET /api/system/logs, G…

▾ Sunlitlin-snow · github.com/lin-snow/ech0EPSS 0.21%via NVD
CVE-2026-79779Medium· 5.3
1mo ago

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.15%via NVD
CVEs tagged “go” — page 9 · VulnSea