golang
207 tracked vulnerabilities.
CVE-2026-42501
HIGH
Malicious module proxy can bypass checksum database in cmd/go
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-42499
HIGH
Quadratic string concatenation in consumePhrase in net/mail
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39836
HIGH
Panic in Dial and LookupPort when handling NUL byte on Windows in net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39826
MEDIUM
Escaper bypass leads to XSS in html/template
May 07, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-39825
MEDIUM
ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
May 07, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-39823
MEDIUM
Bypass of meta content URL escaping causes XSS in html/template
May 07, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-39820
HIGH
Quadratic string concatentation in consumeComment in net/mail
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39819
MEDIUM
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
May 07, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-39817
MEDIUM
Invoking "go tool pack" does not sanitize output paths in cmd/go
May 07, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-33814
HIGH
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33811
HIGH
Crash when handling long CNAME response in net
May 07, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-6863
MEDIUM
HTTP Filestore Endpoints Misapply Permissions Across Organizations
May 06, 2026
CVSS 6.8
EPSS 0.00
CVE-2026-7573
MEDIUM
GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations
May 06, 2026
CVSS 5.0
EPSS 0.00
CVE-2026-7572
MEDIUM
Velociraptor EVTX Parser — Process Crash via Crafted .evtx File
May 06, 2026
CVSS 4.4
EPSS 0.00
CVE-2026-33813
HIGH
Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image
Apr 21, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33812
MEDIUM
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
Apr 21, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-6290
HIGH
Velociraptor Query() Plugin Misapplies Permissions To Orgs
Apr 15, 2026
CVSS 8.0
EPSS 0.00
CVE-2026-33810
HIGH
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Apr 08, 2026
CVSS 8.2
EPSS 0.00
CVE-2026-32289
MEDIUM
JsBraceDepth Context Tracking Bugs (XSS) in html/template
Apr 08, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-32288
MEDIUM
Unbounded allocation for old GNU sparse in archive/tar
Apr 08, 2026
CVSS 5.5
EPSS 0.00
CVE-2026-32283
HIGH
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-32282
MEDIUM
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
Apr 08, 2026
CVSS 6.4
EPSS 0.00
CVE-2026-32281
HIGH
Inefficient policy validation in crypto/x509
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-32280
HIGH
Unexpected work during chain building in crypto/x509
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-27144
HIGH
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Apr 08, 2026
CVSS 7.1
EPSS 0.00