Tagged “go”
CVEs tagged go, newest first.
1732 CVEsRSS
CVE-2026-55678MediumArc is an open, SQL-native time-series database for telemetry
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…
CVE-2026-56854Medium· 6.8golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)
A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…
CVE-2026-55245HighBifrost is an enterprise AI gateway for routing requests to model providers
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, clas…
CVE-2026-55484High· 7.5ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning wi…
CVE-2026-54754Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…
CVE-2026-54755Critical· 9.6Klever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go a…
CVE-2026-55569Medium· 6.6aqua is a declarative command-line version manager written in Go
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains un…
CVE-2026-55834Medium· 4.3Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+pag…
CVE-2026-54766MediumVikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplica…
CVE-2026-55064Medium· 4.3Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to…
CVE-2026-55065High· 8.1Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…
CVE-2026-55066High· 7.1Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket…
CVE-2026-55067Medium· 5.0Vikunja is an open-source self-hosted task management platform
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/model…
CVE-2026-55068Criticalfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…
CVE-2026-54746Medium· 6.4Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…
CVE-2026-55108High· 8.5KubeVela is an open source application delivery platform
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, G…
CVE-2026-42350LowKargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
GHSA-mf7q-r4rv-jv94HighCrossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
CVE-2026-60004Critical· 9.8CISA KEV0dayPoCGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-79921High· 7.5amqp091-go is a Go AMQP 0.9.1 client
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead …
CVE-2026-54563High· 7.1Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
CVE-2026-54523Critical· 9.6Kyverno is a policy engine designed for cloud native platform engineering teams
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …
CVE-2026-54245HighFleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…
CVE-2026-48786Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…
CVE-2026-46370Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…
CVE-2026-46371Medium· 6.5Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…
CVE-2026-41262Medium· 4.3Fleet is an open-source device management platform built on osquery
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…
CVE-2026-55588Medium· 6.5⚖ disputedORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries
ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registr…
CVE-2026-79669Medium· 4.3Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs
Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access historical logs and real-time log streams via GET /api/system/logs, G…
CVE-2026-79779Medium· 5.3rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker obse…