golang

207 tracked vulnerabilities.

CVE-2026-42501 HIGH
Malicious module proxy can bypass checksum database in cmd/go
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-42499 HIGH
Quadratic string concatenation in consumePhrase in net/mail
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39836 HIGH
Panic in Dial and LookupPort when handling NUL byte on Windows in net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39826 MEDIUM
Escaper bypass leads to XSS in html/template
May 07, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-39825 MEDIUM
ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
May 07, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-39823 MEDIUM
Bypass of meta content URL escaping causes XSS in html/template
May 07, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-39820 HIGH
Quadratic string concatentation in consumeComment in net/mail
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39819 MEDIUM
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
May 07, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-39817 MEDIUM
Invoking "go tool pack" does not sanitize output paths in cmd/go
May 07, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-33814 HIGH
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33811 HIGH
Crash when handling long CNAME response in net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-6863 MEDIUM
HTTP Filestore Endpoints Misapply Permissions Across Organizations
May 06, 2026
CVSS 6.8
EPSS 0.00
CVE-2026-7573 MEDIUM
GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations
May 06, 2026
CVSS 5.0
EPSS 0.00
CVE-2026-7572 MEDIUM
Velociraptor EVTX Parser — Process Crash via Crafted .evtx File
May 06, 2026
CVSS 4.4
EPSS 0.00
CVE-2026-33813 HIGH
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
Apr 21, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33812 MEDIUM
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
Apr 21, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-6290 HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
Apr 15, 2026
CVSS 8.0
EPSS 0.00
CVE-2026-33810 HIGH
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Apr 08, 2026
CVSS 8.2
EPSS 0.00
CVE-2026-32289 MEDIUM
JsBraceDepth Context Tracking Bugs (XSS) in html/template
Apr 08, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-32288 MEDIUM
Unbounded allocation for old GNU sparse in archive/tar
Apr 08, 2026
CVSS 5.5
EPSS 0.00
CVE-2026-32283 HIGH
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-32282 MEDIUM
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
Apr 08, 2026
CVSS 6.4
EPSS 0.00
CVE-2026-32281 HIGH
Inefficient policy validation in crypto/x509
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-32280 HIGH
Unexpected work during chain building in crypto/x509
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-27144 HIGH
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Apr 08, 2026
CVSS 7.1
EPSS 0.00