Go incidents

Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MEDIUMGo

Anubis: Policy bypass via client controlled X-Original-URI header

Anubis: Policy bypass via client controlled X-Original-URI header

3 days ago
HIGHGo

SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers

SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers

3 days ago
CRITICALGo

gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled

gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled

3 days ago
LOWGo

SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass

SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass

3 days ago
UNKNOWNGo

Malicious code in gocommunity.io/orderedbtree (Go)

Malicious code in gocommunity.io/orderedbtree (Go)

3 days ago
HIGHGo

Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks

Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks

3 days ago
HIGHGo

SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

3 days ago
UNKNOWNGo

Malicious code in gogets.dev/btreex (Go)

Malicious code in gogets.dev/btreex (Go)

3 days ago
HIGHGo

SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

3 days ago
UNKNOWNGo

SIPGO: DoS via unvalidated WebSocket frame length in github.com/emiago/sipgo

SIPGO: DoS via unvalidated WebSocket frame length in github.com/emiago/sipgo

4 days ago
UNKNOWNGo

OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log

OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope in github.com/cloudreve/Cloudreve

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope in github.com/cloudreve/Cloudreve

4 days ago
MEDIUMGo

SiYuan discloses an administrator's open documents and search terms to anonymous readers

SiYuan discloses an administrator's open documents and search terms to anonymous readers

4 days ago
UNKNOWNGo

OpenShift Cluster Logging Operator missing authorization flaw in github.com/openshift/cluster-logging-operator

OpenShift Cluster Logging Operator missing authorization flaw in github.com/openshift/cluster-logging-operator

4 days ago
UNKNOWNGo

Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd

Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd

4 days ago
UNKNOWNGo

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet

4 days ago
UNKNOWNGo

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium

4 days ago
UNKNOWNGo

Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go

Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go

4 days ago
UNKNOWNGo

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet

4 days ago
UNKNOWNGo

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability in github.com/projectdiscovery/nuclei

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability in github.com/projectdiscovery/nuclei

4 days ago
MEDIUMGo

SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering

SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go

4 days ago
MEDIUMGo

SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check

SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check

4 days ago
UNKNOWNGo

Klever-Go: /log controls global node logging in github.com/klever-io/klever-go

Klever-Go: /log controls global node logging in github.com/klever-io/klever-go

4 days ago
MEDIUMGo

SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem

SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem

4 days ago
UNKNOWNGo

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses in github.com/cloudreve/Cloudreve

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses in github.com/cloudreve/Cloudreve

4 days ago
UNKNOWNGo

Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer

Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf

fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf

4 days ago
UNKNOWNGo

podman quadlet install --replace does not fully replace the old file in github.com/containers/podman

podman quadlet install --replace does not fully replace the old file in github.com/containers/podman

4 days ago
UNKNOWNGo

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge

4 days ago
UNKNOWNGo

Podman: Malformed Image can trick podman run into leaking host environment variables into the container in github.com/containers/libpod

Podman: Malformed Image can trick podman run into leaking host environment variables into the container in github.com/containers/libpod

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

Gardener: Authorization Bypass via Group Subject Injection in gardener/gardener

Gardener: Authorization Bypass via Group Subject Injection in gardener/gardener

4 days ago
UNKNOWNGo

Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle

Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle

4 days ago
UNKNOWNGo

Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS in github.com/tomwright/dasel

Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS in github.com/tomwright/dasel

4 days ago
UNKNOWNGo

Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` in github.com/tomwright/dasel

Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` in github.com/tomwright/dasel

4 days ago
UNKNOWNGo

SIPGO: DoS via unvalidated Content-Length in the stream parser in github.com/emiago/sipgo

SIPGO: DoS via unvalidated Content-Length in the stream parser in github.com/emiago/sipgo

4 days ago
UNKNOWNGo

ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel

ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

Tinyauth: User enumeration attack by timing oracle in github.com/tinyauthapp/tinyauth

Tinyauth: User enumeration attack by timing oracle in github.com/tinyauthapp/tinyauth

4 days ago
UNKNOWNGo

ZITADEL: MFA bypass via session reuse in Login V2 in github.com/zitadel/zitadel

ZITADEL: MFA bypass via session reuse in Login V2 in github.com/zitadel/zitadel

4 days ago
UNKNOWNGo

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes in github.com/kubeedge/kubeedge

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes in github.com/kubeedge/kubeedge

4 days ago
UNKNOWNGo

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

4 days ago
UNKNOWNGo

Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller in github.com/klever-io/klever-go

Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller in github.com/klever-io/klever-go

4 days ago
UNKNOWNGo

OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace

OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace

4 days ago
UNKNOWNGo

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass in github.com/projectdiscovery/nuclei

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass in github.com/projectdiscovery/nuclei

4 days ago
UNKNOWNGo

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass in github.com/projectdiscovery/nuclei

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass in github.com/projectdiscovery/nuclei

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) in github.com/klever-io/klever-go

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) in github.com/klever-io/klever-go

4 days ago
UNKNOWNGo

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth

4 days ago
UNKNOWNGo

OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters in github.com/openbao/openbao

OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters in github.com/openbao/openbao

4 days ago
UNKNOWNGo

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio

4 days ago
UNKNOWNGo

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet

4 days ago
UNKNOWNGo

Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go

Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go

4 days ago
UNKNOWNGo

KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub in github.com/kubeedge/kubeedge

KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub in github.com/kubeedge/kubeedge

4 days ago
UNKNOWNGo

OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack in github.com/openbao/openbao

OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack in github.com/openbao/openbao

4 days ago
UNKNOWNGo

Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS in github.com/klever-io/klever-go

Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS in github.com/klever-io/klever-go

4 days ago
UNKNOWNGo

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet

4 days ago
UNKNOWNGo

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join in github.com/kubeedge/kubeedge

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join in github.com/kubeedge/kubeedge

4 days ago
UNKNOWNGo

Vulnerabilities in handler/placeholder layer in github.com/caddyserver/caddy

Vulnerabilities in handler/placeholder layer in github.com/caddyserver/caddy

4 days ago
UNKNOWNGo

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth

4 days ago
UNKNOWNGo

Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace in github.com/klever-io/klever-go

Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace in github.com/klever-io/klever-go

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

OpenBao Skips Stricter Deny Policy for LIST operations in github.com/openbao/openbao

OpenBao Skips Stricter Deny Policy for LIST operations in github.com/openbao/openbao

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass in github.com/ixofoundation/ixo-blockchain

ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass in github.com/ixofoundation/ixo-blockchain

4 days ago
UNKNOWNGo

OpenBao Agent Writes Secrets to Stdout in github.com/openbao/openbao

OpenBao Agent Writes Secrets to Stdout in github.com/openbao/openbao

4 days ago
UNKNOWNGo

Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle

Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle

4 days ago
MEDIUMGo

SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block

SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block

4 days ago
UNKNOWNGo

Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery in github.com/klever-io/klever-go

Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery in github.com/klever-io/klever-go

4 days ago
UNKNOWNGo

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk

4 days ago
HIGHGo

SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route

SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route

4 days ago
UNKNOWNGo

Nuclei: Local File Read via MySQL Client Sandbox Bypass in github.com/projectdiscovery/nuclei

Nuclei: Local File Read via MySQL Client Sandbox Bypass in github.com/projectdiscovery/nuclei

4 days ago
HIGHGo

SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking

SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking

4 days ago
UNKNOWNGo

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service in github.com/cloudreve/Cloudreve

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service in github.com/cloudreve/Cloudreve

4 days ago
UNKNOWNGo

RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go

RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go

4 days ago
UNKNOWNGo

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode in github.com/projectdiscovery/nuclei

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode in github.com/projectdiscovery/nuclei

4 days ago
MODERATEGo

OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full

OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full

6 days ago
MODERATEGo

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

6 days ago
MODERATEGo

Containerd has image-pull DoS via crafted OCI index graph amplification

Containerd has image-pull DoS via crafted OCI index graph amplification

1 week ago
MEDIUMGo

podman quadlet install --replace does not fully replace the old file

podman quadlet install --replace does not fully replace the old file

1 week ago
MEDIUMGo

Dozzle label filters do not restrict container event and statistics streams

Dozzle label filters do not restrict container event and statistics streams

1 week ago
HIGHGo

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

1 week ago
MEDIUMGo

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces

1 week ago
HIGHGo

ZITADEL: Actions V1 sandbox escape: host file read via require()

ZITADEL: Actions V1 sandbox escape: host file read via require()

1 week ago
CRITICALGo

ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass

ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass

1 week ago
HIGHGo

ZITADEL: MFA bypass via session reuse in Login V2

ZITADEL: MFA bypass via session reuse in Login V2

1 week ago
HIGHGo

Klever-Go: /log controls global node logging

Klever-Go: /log controls global node logging

1 week ago
HIGHGo

Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery

Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery

1 week ago
HIGHGo

Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller

Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller

1 week ago
HIGHGo

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)

Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)

1 week ago
HIGHGo

Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS

Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS

1 week ago
HIGHGo

Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

1 week ago
HIGHGo

Nuclei: Local File Read via MySQL Client Sandbox Bypass

Nuclei: Local File Read via MySQL Client Sandbox Bypass

1 week ago
CRITICALGo

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API

KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API

1 week ago
HIGHGo

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode

Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode

1 week ago
HIGHGo

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for

Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for

1 week ago
HIGHGo

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service

1 week ago
CRITICALGo

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability

1 week ago
CRITICALGo

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

1 week ago
HIGHGo

SIPGO: DoS via unvalidated Content-Length in the stream parser

SIPGO: DoS via unvalidated Content-Length in the stream parser

1 week ago
MEDIUMGo

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service

1 week ago
HIGHGo

Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`

Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`

1 week ago
HIGHGo

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

1 week ago
CRITICALGo

OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack

OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack

1 week ago
MEDIUMGo

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher

Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher

1 week ago
HIGHGo

Gardener: Authorization Bypass via Group Subject Injection

Gardener: Authorization Bypass via Group Subject Injection

1 week ago
MODERATEGo

Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle

Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle

1 week ago
MODERATEGo

Tinyauth: User enumeration attack by timing oracle

Tinyauth: User enumeration attack by timing oracle

1 week ago
HIGHGo

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

1 week ago
HIGHGo

KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub

KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub

1 week ago
HIGHGo

Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS

Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS

1 week ago
HIGHGo

OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters

OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters

1 week ago
HIGHGo

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses

1 week ago
MEDIUMGo

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope

1 week ago
MODERATEGo

OpenBao Skips Stricter Deny Policy for LIST operations

OpenBao Skips Stricter Deny Policy for LIST operations

1 week ago
MEDIUMGo

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler

Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler

1 week ago
HIGHGo

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass

Nuclei: Local File Read via Workflow File-Protocol Gate Bypass

1 week ago
HIGHGo

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check

1 week ago
LOWGo

OpenBao Agent Writes Secrets to Stdout

OpenBao Agent Writes Secrets to Stdout

1 week ago
MEDIUMGo

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter

1 week ago
HIGHGo

SIPGO: DoS via unvalidated WebSocket frame length

SIPGO: DoS via unvalidated WebSocket frame length

1 week ago
MEDIUMGo

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header

1 week ago
HIGHGo

zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion

zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion

2 weeks ago
HIGHGo

Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

Perses's missing authorization in datasource proxy allows cross-scope secret disclosure

2 weeks ago
MEDIUMGo

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

2 weeks ago
HIGHGo

Perses's project query parameter authorization bypass exposes cross-project resources

Perses's project query parameter authorization bypass exposes cross-project resources

2 weeks ago
HIGHGo

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

2 weeks ago
CRITICALGo

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

2 weeks ago
HIGHGo

Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

2 weeks ago
HIGHGo

Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

2 weeks ago
HIGHGo

Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

2 weeks ago
HIGHGo

Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

2 weeks ago
CRITICALGo

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace

2 weeks ago
MODERATEGo

Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools

Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools

2 weeks ago
MEDIUMGo

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

2 weeks ago
CRITICALGo

ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement

ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement

2 weeks ago
HIGHGo

Perses's unvalidated project parameter enables filesystem path traversal

Perses's unvalidated project parameter enables filesystem path traversal

2 weeks ago
HIGHGo

AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

2 weeks ago
HIGHGo

AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields

RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields

2 weeks ago
CRITICALGo

RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser

RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation

2 weeks ago
HIGHGo

Pocketbase: Unhandled panic in worker goroutines

Pocketbase: Unhandled panic in worker goroutines

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation

RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation

2 weeks ago
HIGHGo

CoreDNS: Unauthenticated memory exhaustion in custom transports

CoreDNS: Unauthenticated memory exhaustion in custom transports

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

2 weeks ago
CRITICALGo

oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

2 weeks ago
HIGHGo

CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

2 weeks ago
LOWGo

OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs

OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs

2 weeks ago
CRITICALGo

RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr

RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr

2 weeks ago
MODERATEGo

OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning

OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning

2 weeks ago
HIGHGo

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

2 weeks ago
MEDIUMGo

oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing

oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing

2 weeks ago
CRITICALGo

RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow

RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow

2 weeks ago
HIGHGo

Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)

2 weeks ago
UNKNOWNGo

rclone: http backend forwards custom/auth headers to a different host on redirect in github.com/rclone/rclone

rclone: http backend forwards custom/auth headers to a different host on redirect in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel

ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel

2 weeks ago
UNKNOWNGo

Joker linter executed project-local .jokerd/linter.* files during linting in github.com/candid82/joker

Joker linter executed project-local .jokerd/linter.* files during linting in github.com/candid82/joker

2 weeks ago
UNKNOWNGo

rclone: S3 multipart declared-length memory exhaustion in github.com/rclone/rclone

rclone: S3 multipart declared-length memory exhaustion in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint in github.com/lf-edge/ekuiper

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint in github.com/lf-edge/ekuiper

2 weeks ago
UNKNOWNGo

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass in github.com/rclone/rclone

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Panic via negative shared-string index in github.com/xuri/excelize

Panic via negative shared-string index in github.com/xuri/excelize

2 weeks ago
UNKNOWNGo

rclone local: crafted Range request against a translated symlink panics (DoS) in github.com/rclone/rclone

rclone local: crafted Range request against a translated symlink panics (DoS) in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel

2 weeks ago
UNKNOWNGo

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel

2 weeks ago
UNKNOWNGo

rclone: source object names can escape the configured root on upload in github.com/rclone/rclone

rclone: source object names can escape the configured root on upload in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Komari: Management Interface CSRF in github.com/komari-monitor/komari

Komari: Management Interface CSRF in github.com/komari-monitor/komari

2 weeks ago
UNKNOWNGo

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

rclone: RC per-server auth-proxy bypass in github.com/rclone/rclone

rclone: RC per-server auth-proxy bypass in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Traefik entrypoint header-name sanitization bypassed via request trailers in github.com/traefik/traefik

Traefik entrypoint header-name sanitization bypassed via request trailers in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik

Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik

2 weeks ago
HIGHGo

OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user

OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user

2 weeks ago
UNKNOWNGo

rclone: FTP cross-session auth-proxy backend confusion in github.com/rclone/rclone

rclone: FTP cross-session auth-proxy backend confusion in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

LF Edge eKuiper: SSRF in External Service in github.com/lf-edge/ekuiper

LF Edge eKuiper: SSRF in External Service in github.com/lf-edge/ekuiper

2 weeks ago
UNKNOWNGo

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace in github.com/rclone/rclone

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

webhookd: Unrestricted HTTP Header to Shell Variable Injection in github.com/ncarlier/webhookd

webhookd: Unrestricted HTTP Header to Shell Variable Injection in github.com/ncarlier/webhookd

2 weeks ago
UNKNOWNGo

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel

2 weeks ago
UNKNOWNGo

LF Edge eKuiper: Self-XSS in External Service Creation in github.com/lf-edge/ekuiper

LF Edge eKuiper: Self-XSS in External Service Creation in github.com/lf-edge/ekuiper

2 weeks ago
UNKNOWNGo

Traefik HTTP/3 Backend NTLM Connection Reuse in github.com/traefik/traefik

Traefik HTTP/3 Backend NTLM Connection Reuse in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging in github.com/traefik/traefik

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Unbounded memory allocation via streaming row reader in github.com/xuri/excelize

Unbounded memory allocation via streaming row reader in github.com/xuri/excelize

2 weeks ago
UNKNOWNGo

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification in github.com/identrail/identrail

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification in github.com/identrail/identrail

2 weeks ago
UNKNOWNGo

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd

2 weeks ago
UNKNOWNGo

Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc

Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc

2 weeks ago
UNKNOWNGo

Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics

Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics

2 weeks ago
MODERATEGo

Netmaker has a boolean‑based SQL Injection

Netmaker has a boolean‑based SQL Injection

2 weeks ago
UNKNOWNGo

Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go

Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go

2 weeks ago
UNKNOWNGo

Missing authorization on vttablet /debug/vrlog in vitess.io/vitess

Missing authorization on vttablet /debug/vrlog in vitess.io/vitess

2 weeks ago
HIGHGo

emp3r0r has an unauthenticated HTTP Polling DoS

emp3r0r has an unauthenticated HTTP Polling DoS

2 weeks ago
UNKNOWNGo

Server panic via missing authority or Host headers in google.golang.org/grpc

Server panic via missing authority or Host headers in google.golang.org/grpc

2 weeks ago
UNKNOWNGo

Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc

Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc

2 weeks ago
LOWGo

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

2 weeks ago
HIGHGo

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

3 weeks ago
HIGHGo

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

3 weeks ago
MEDIUMGo

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

3 weeks ago
MEDIUMGo

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

3 weeks ago
UNKNOWNGo

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
HIGHGo

rclone: S3 multipart declared-length memory exhaustion

rclone: S3 multipart declared-length memory exhaustion

3 weeks ago
HIGHGo

rclone: source object names can escape the configured root on upload

rclone: source object names can escape the configured root on upload

3 weeks ago
UNKNOWNGo

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList

3 weeks ago
UNKNOWNGo

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox

3 weeks ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

3 weeks ago
UNKNOWNGo

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium

3 weeks ago
HIGHGo

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

3 weeks ago
UNKNOWNGo

Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

3 weeks ago
UNKNOWNGo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo

3 weeks ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
CRITICALGo

Traefik HTTP/3 Backend NTLM Connection Reuse

Traefik HTTP/3 Backend NTLM Connection Reuse

3 weeks ago
UNKNOWNGo

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

3 weeks ago
HIGHGo

Traefik entrypoint header-name sanitization bypassed via request trailers

Traefik entrypoint header-name sanitization bypassed via request trailers

3 weeks ago
UNKNOWNGo

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

3 weeks ago
HIGHGo

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

3 weeks ago
UNKNOWNGo

Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

3 weeks ago
UNKNOWNGo

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

3 weeks ago
HIGHGo

Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

3 weeks ago
UNKNOWNGo

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost

3 weeks ago
UNKNOWNGo

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore

3 weeks ago
HIGHGo

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

3 weeks ago
UNKNOWNGo

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo

3 weeks ago
UNKNOWNGo

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit

3 weeks ago
UNKNOWNGo

Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

3 weeks ago
UNKNOWNGo

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore

3 weeks ago
UNKNOWNGo

ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf

ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf

3 weeks ago
UNKNOWNGo

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit

3 weeks ago
UNKNOWNGo

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

3 weeks ago
UNKNOWNGo

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost

Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost

3 weeks ago
UNKNOWNGo

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle

3 weeks ago
UNKNOWNGo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo

3 weeks ago
UNKNOWNGo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo

3 weeks ago
UNKNOWNGo

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore

Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore

3 weeks ago
MODERATEGo

Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

3 weeks ago
MEDIUMGo

rclone local: crafted Range request against a translated symlink panics (DoS)

rclone local: crafted Range request against a translated symlink panics (DoS)

3 weeks ago
UNKNOWNGo

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo

3 weeks ago
UNKNOWNGo

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

3 weeks ago
UNKNOWNGo

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

3 weeks ago
MEDIUMGo

rclone: http backend forwards custom/auth headers to a different host on redirect

rclone: http backend forwards custom/auth headers to a different host on redirect

3 weeks ago
MODERATEGo

Traefik: ForwardAuth identity spoofing via dot-form header alias

Traefik: ForwardAuth identity spoofing via dot-form header alias

3 weeks ago
UNKNOWNGo

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs

3 weeks ago
UNKNOWNGo

Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

3 weeks ago
HIGHGo

rclone: FTP cross-session auth-proxy backend confusion

rclone: FTP cross-session auth-proxy backend confusion

3 weeks ago
UNKNOWNGo

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

3 weeks ago
UNKNOWNGo

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

3 weeks ago
MEDIUMGo

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

3 weeks ago
HIGHGo

rclone: RC per-server auth-proxy bypass

rclone: RC per-server auth-proxy bypass

3 weeks ago
CRITICALGo

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

3 weeks ago
UNKNOWNGo

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

3 weeks ago
HIGHGo

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

3 weeks ago
CRITICALGo

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

3 weeks ago
HIGHGo

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

3 weeks ago
UNKNOWNGo

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

3 weeks ago
MEDIUMGo

webhookd: Unrestricted HTTP Header to Shell Variable Injection

webhookd: Unrestricted HTTP Header to Shell Variable Injection

3 weeks ago
HIGHGo

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

3 weeks ago
HIGHGo

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

3 weeks ago
CRITICALGo

Komari: Management Interface CSRF

Komari: Management Interface CSRF

3 weeks ago
MEDIUMGo

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

3 weeks ago
MODERATEGo

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

3 weeks ago
MODERATEGo

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

3 weeks ago
HIGHGo

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

3 weeks ago
HIGHGo

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

3 weeks ago
CRITICALGo

Semaphore U: OS Command Injection

Semaphore U: OS Command Injection

3 weeks ago
MODERATEGo

Infracost: Arbitrary file read via config-template readFile symlink traversal

Infracost: Arbitrary file read via config-template readFile symlink traversal

3 weeks ago
LOWGo

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

3 weeks ago
MODERATEGo

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

3 weeks ago
MEDIUMGo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

3 weeks ago
CRITICALGo

Gitea: Remote Code Execution via diffpatch Git Hook Installation

Gitea: Remote Code Execution via diffpatch Git Hook Installation

3 weeks ago
MEDIUMGo

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

3 weeks ago
HIGHGo

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

4 weeks ago
MEDIUMGo

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

4 weeks ago
HIGHGo

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

4 weeks ago
HIGHGo

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

4 weeks ago
MEDIUMGo

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

4 weeks ago
CRITICALGo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

4 weeks ago
HIGHGo

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

4 weeks ago
MEDIUMGo

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

4 weeks ago
MEDIUMGo

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers

4 weeks ago
HIGHGo

VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root

VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root

4 weeks ago
HIGHGo

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

4 weeks ago
MEDIUMGo

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

4 weeks ago
HIGHGo

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

4 weeks ago
MEDIUMGo

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

4 weeks ago
HIGHGo

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

4 weeks ago
MEDIUMGo

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

4 weeks ago
HIGHGo

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

4 weeks ago
MEDIUMGo

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

4 weeks ago
HIGHGo

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

4 weeks ago
HIGHGo

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

4 weeks ago
MEDIUMGo

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

4 weeks ago
HIGHGo

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

4 weeks ago
MEDIUMGo

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

4 weeks ago
CRITICALGo

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

4 weeks ago
HIGHGo

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

4 weeks ago
HIGHGo

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

4 weeks ago
HIGHGo

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

4 weeks ago
MEDIUMGo

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

4 weeks ago
HIGHGo

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

4 weeks ago
MEDIUMGo

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

4 weeks ago
HIGHGo

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

4 weeks ago
HIGHGo

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

4 weeks ago
HIGHGo

ffuf denial of service (OOM) via HTTP response decompression bomb

ffuf denial of service (OOM) via HTTP response decompression bomb

4 weeks ago
HIGHGo

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

4 weeks ago
HIGHGo

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

4 weeks ago
HIGHGo

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

4 weeks ago
HIGHGo

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

4 weeks ago
MEDIUMGo

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

4 weeks ago
UNKNOWNGo

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api

4 weeks ago
UNKNOWNGo

Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus

Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus

4 weeks ago
UNKNOWNGo

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

4 weeks ago
UNKNOWNGo

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go

4 weeks ago
CRITICALGo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

4 weeks ago
UNKNOWNGo

Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea

Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea

4 weeks ago
HIGHGo

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

4 weeks ago
HIGHGo

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection

4 weeks ago
UNKNOWNGo

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api

4 weeks ago
UNKNOWNGo

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api

4 weeks ago
UNKNOWNGo

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

4 weeks ago
UNKNOWNGo

KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela

KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela

4 weeks ago
UNKNOWNGo

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go

4 weeks ago
UNKNOWNGo

Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus

Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus

4 weeks ago
UNKNOWNGo

Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea

Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras

4 weeks ago
UNKNOWNGo

Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea

Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet

4 weeks ago
UNKNOWNGo

Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api

Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api

4 weeks ago
UNKNOWNGo

Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea

Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go

4 weeks ago
UNKNOWNGo

Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea

Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua

4 weeks ago
UNKNOWNGo

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer

4 weeks ago
UNKNOWNGo

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc

4 weeks ago
UNKNOWNGo

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api

4 weeks ago
UNKNOWNGo

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf

4 weeks ago
UNKNOWNGo

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc

4 weeks ago
UNKNOWNGo

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http

4 weeks ago
UNKNOWNGo

Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea

Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core

4 weeks ago
UNKNOWNGo

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go

4 weeks ago
UNKNOWNGo

Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea

Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend

4 weeks ago
UNKNOWNGo

Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea

Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf

4 weeks ago
HIGHGo

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling

4 weeks ago
UNKNOWNGo

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs

4 weeks ago
UNKNOWNGo

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs

4 weeks ago
HIGHGo

Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends

Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends

4 weeks ago
UNKNOWNGo

Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo

Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo

4 weeks ago
CRITICALGo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

4 weeks ago
HIGHGo

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

4 weeks ago
HIGHGo

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

4 weeks ago
MEDIUMGo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

4 weeks ago
CRITICALGo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

4 weeks ago
CRITICALGo

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

4 weeks ago
UNKNOWNGo

Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea

Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea

4 weeks ago
UNKNOWNGo

Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea

Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea

4 weeks ago
HIGHGo

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

4 weeks ago
HIGHGo

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

1 month ago
HIGHGo

Incus has a project restriction bypass for custom volume copy across projects

Incus has a project restriction bypass for custom volume copy across projects

1 month ago
MEDIUMGo

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment

1 month ago
HIGHGo

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id

1 month ago
HIGHGo

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)

1 month ago
MEDIUMGo

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe

1 month ago
HIGHGo

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

1 month ago
HIGHGo

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

1 month ago
HIGHGo

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

1 month ago
MEDIUMGo

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption

1 month ago
HIGHGo

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

1 month ago
HIGHGo

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

1 month ago
MEDIUMGo

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

1 month ago
HIGHGo

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory

1 month ago
HIGHGo

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

1 month ago
HIGHGo

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

1 month ago
MODERATEGo

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset

1 month ago
CRITICALGo

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints

1 month ago
HIGHGo

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

1 month ago
MEDIUMGo

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

1 month ago
MODERATEGo

Vikunja has a project duplication bypasses write-permission check on the target parent project

Vikunja has a project duplication bypasses write-permission check on the target parent project

1 month ago
UNKNOWNGo

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

1 month ago
HIGHGo

KubeVela Terraform remote loader DoS via unbounded file read

KubeVela Terraform remote loader DoS via unbounded file read

1 month ago
MEDIUMGo

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

1 month ago
MEDIUMGo

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

1 month ago
HIGHGo

Incus has a project restriction bypass in instance copy across projects

Incus has a project restriction bypass in instance copy across projects

1 month ago
UNKNOWNGo

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server

1 month ago
UNKNOWNGo

Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash

Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash

1 month ago
UNKNOWNGo

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

1 month ago
LOWGo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

1 month ago
UNKNOWNGo

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng

1 month ago
UNKNOWNGo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo

1 month ago
HIGHGo

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

1 month ago
UNKNOWNGo

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno

1 month ago
UNKNOWNGo

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell

1 month ago
UNKNOWNGo

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp

1 month ago
UNKNOWNGo

Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5

Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5

1 month ago
HIGHGo

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

1 month ago
UNKNOWNGo

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

1 month ago
UNKNOWNGo

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell

1 month ago
HIGHGo

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system

1 month ago
UNKNOWNGo

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell

1 month ago
UNKNOWNGo

MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox

MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox

1 month ago
UNKNOWNGo

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

1 month ago
UNKNOWNGo

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit

1 month ago
UNKNOWNGo

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

1 month ago
UNKNOWNGo

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

1 month ago
UNKNOWNGo

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

1 month ago
UNKNOWNGo

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

1 month ago
UNKNOWNGo

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget

1 month ago
UNKNOWNGo

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember

1 month ago
UNKNOWNGo

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

1 month ago
UNKNOWNGo

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy

1 month ago
UNKNOWNGo

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

1 month ago
CRITICALGo

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias

1 month ago
UNKNOWNGo

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code

1 month ago
UNKNOWNGo

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet

1 month ago
HIGHGo

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

1 month ago
UNKNOWNGo

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

1 month ago
HIGHGo

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

1 month ago
UNKNOWNGo

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

1 month ago
UNKNOWNGo

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

1 month ago
UNKNOWNGo

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

1 month ago
UNKNOWNGo

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi

1 month ago
UNKNOWNGo

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing

1 month ago
UNKNOWNGo

moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive

moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive

1 month ago
UNKNOWNGo

BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit

BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit

1 month ago
UNKNOWNGo

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

1 month ago
CRITICALGo

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

1 month ago
HIGHGo

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport

1 month ago
UNKNOWNGo

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

1 month ago
UNKNOWNGo

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi

1 month ago
UNKNOWNGo

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy

1 month ago
UNKNOWNGo

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis

1 month ago
UNKNOWNGo

BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit

BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit

1 month ago
UNKNOWNGo

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

1 month ago
UNKNOWNGo

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

1 month ago
UNKNOWNGo

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

1 month ago
UNKNOWNGo

Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero

Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero

1 month ago
UNKNOWNGo

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit

1 month ago
UNKNOWNGo

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code

1 month ago
HIGHGo

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

1 month ago
MODERATEGo

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

1 month ago
LOWGo

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

1 month ago
MEDIUMGo

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

1 month ago
CRITICALGo

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

1 month ago
MODERATEGo

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

1 month ago
HIGHGo

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

1 month ago
HIGHGo

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

1 month ago
HIGHGo

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

1 month ago
MEDIUMGo

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

1 month ago
HIGHGo

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

1 month ago
MEDIUMGo

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

1 month ago
MEDIUMGo

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

1 month ago
HIGHGo

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

1 month ago
MEDIUMGo

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

1 month ago
HIGHGo

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

1 month ago
HIGHGo

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

1 month ago
HIGHGo

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

1 month ago
HIGHGo

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

1 month ago
MODERATEGo

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

1 month ago
MODERATEGo

Velero vulnerable to file path traversal when extracting from backup's tarball

Velero vulnerable to file path traversal when extracting from backup's tarball

1 month ago
MEDIUMGo

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

1 month ago
MEDIUMGo

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

1 month ago
MEDIUMGo

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

1 month ago
MODERATEGo

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

1 month ago
LOWGo

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

1 month ago
MODERATEGo

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

1 month ago
UNKNOWNGo

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

1 month ago
HIGHGo

moby/go-archive: Crafted tar archive can write outside the extraction directory

moby/go-archive: Crafted tar archive can write outside the extraction directory

1 month ago
UNKNOWNGo

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

1 month ago
UNKNOWNGo

Watch API authorization bypass in go.etcd.io/etcd/server/v3

Watch API authorization bypass in go.etcd.io/etcd/server/v3

1 month ago
UNKNOWNGo

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

1 month ago
UNKNOWNGo

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

1 month ago
UNKNOWNGo

Integer overflow in BTF parsing in github.com/cilium/ebpf

Integer overflow in BTF parsing in github.com/cilium/ebpf

1 month ago
UNKNOWNGo

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

1 month ago
UNKNOWNGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

1 month ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

1 month ago
UNKNOWNGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

1 month ago
UNKNOWNGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

1 month ago
UNKNOWNGo

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

1 month ago
UNKNOWNGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

1 month ago
UNKNOWNGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

1 month ago
UNKNOWNGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

1 month ago
UNKNOWNGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

1 month ago
UNKNOWNGo

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

1 month ago
UNKNOWNGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

1 month ago
UNKNOWNGo

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

1 month ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

1 month ago
UNKNOWNGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

1 month ago
UNKNOWNGo

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

1 month ago
UNKNOWNGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

1 month ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

1 month ago
MEDIUMGo

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

1 month ago
UNKNOWNGo

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

1 month ago
UNKNOWNGo

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

1 month ago
UNKNOWNGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

1 month ago
UNKNOWNGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

1 month ago
UNKNOWNGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

1 month ago
UNKNOWNGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

1 month ago
UNKNOWNGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

1 month ago
UNKNOWNGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

1 month ago
UNKNOWNGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

1 month ago
UNKNOWNGo

goshs has a Path Traversal issue in github.com/patrickhener/goshs

goshs has a Path Traversal issue in github.com/patrickhener/goshs

1 month ago
UNKNOWNGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

1 month ago
UNKNOWNGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

1 month ago
UNKNOWNGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

1 month ago
UNKNOWNGo

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

1 month ago
UNKNOWNGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

1 month ago
UNKNOWNGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

1 month ago
UNKNOWNGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

1 month ago
UNKNOWNGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

1 month ago
UNKNOWNGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

1 month ago
UNKNOWNGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

1 month ago
UNKNOWNGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

1 month ago
UNKNOWNGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

1 month ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

1 month ago
UNKNOWNGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

1 month ago
UNKNOWNGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

1 month ago
UNKNOWNGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

1 month ago
UNKNOWNGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

1 month ago
UNKNOWNGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

1 month ago
UNKNOWNGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

1 month ago
UNKNOWNGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

1 month ago
UNKNOWNGo

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

1 month ago
UNKNOWNGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

1 month ago
UNKNOWNGo

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

1 month ago
UNKNOWNGo

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

1 month ago
UNKNOWNGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

1 month ago
UNKNOWNGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

1 month ago
UNKNOWNGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

1 month ago
UNKNOWNGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

1 month ago
UNKNOWNGo

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

1 month ago
UNKNOWNGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

1 month ago
UNKNOWNGo

Path traversal in serve s3 in github.com/rclone/rclone

Path traversal in serve s3 in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

1 month ago
UNKNOWNGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

1 month ago
UNKNOWNGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

1 month ago
UNKNOWNGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

1 month ago
UNKNOWNGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

1 month ago
UNKNOWNGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

1 month ago
UNKNOWNGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

1 month ago
UNKNOWNGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

1 month ago
UNKNOWNGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

1 month ago
UNKNOWNGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

1 month ago
UNKNOWNGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

1 month ago
UNKNOWNGo

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

1 month ago
UNKNOWNGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

1 month ago
UNKNOWNGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

1 month ago
UNKNOWNGo

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

1 month ago
UNKNOWNGo

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

1 month ago
UNKNOWNGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

1 month ago
UNKNOWNGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

1 month ago
UNKNOWNGo

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

1 month ago
UNKNOWNGo

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

1 month ago
UNKNOWNGo

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

1 month ago
UNKNOWNGo

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

1 month ago
UNKNOWNGo

Worktree operations may follow symlinks in github.com/go-git/go-git

Worktree operations may follow symlinks in github.com/go-git/go-git

1 month ago
UNKNOWNGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

1 month ago
UNKNOWNGo

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Path traversal via crafted reference names in github.com/go-git/go-git

Path traversal via crafted reference names in github.com/go-git/go-git

1 month ago
UNKNOWNGo

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

1 month ago
UNKNOWNGo

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

1 month ago
UNKNOWNGo

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

1 month ago
UNKNOWNGo

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

1 month ago
UNKNOWNGo

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

1 month ago
UNKNOWNGo

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

1 month ago
UNKNOWNGo

Authorization bypass in serve restic in github.com/rclone/rclone

Authorization bypass in serve restic in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Unsafe file permission restoration from metadata in github.com/rclone/rclone

Unsafe file permission restoration from metadata in github.com/rclone/rclone

1 month ago
UNKNOWNGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

1 month ago
UNKNOWNGo

Arbitrary file write via --links symlinks in github.com/rclone/rclone

Arbitrary file write via --links symlinks in github.com/rclone/rclone

1 month ago
UNKNOWNGo

FTP command injection via custom encoding in github.com/rclone/rclone

FTP command injection via custom encoding in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Path traversal via crafted archive paths in github.com/rclone/rclone

Path traversal via crafted archive paths in github.com/rclone/rclone

1 month ago
MODERATEGo

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

1 month ago
UNKNOWNGo

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

1 month ago
UNKNOWNGo

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Path traversal via local backend encoding in github.com/rclone/rclone

Path traversal via local backend encoding in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Command execution via PowerShell smart quotes in github.com/rclone/rclone

Command execution via PowerShell smart quotes in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Path traversal in serve restic in github.com/rclone/rclone

Path traversal in serve restic in github.com/rclone/rclone

1 month ago
UNKNOWNGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

1 month ago
UNKNOWNGo

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

1 month ago
UNKNOWNGo

Stale blob descriptor cache invalidation in github.com/distribution/distribution

Stale blob descriptor cache invalidation in github.com/distribution/distribution

1 month ago
MODERATEGo

uniget CLI has an EDITOR Command Injection

uniget CLI has an EDITOR Command Injection

1 month ago
MODERATEGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

1 month ago
MODERATEGo

package pkcs12: Authentication bypass in Decode functions

package pkcs12: Authentication bypass in Decode functions

1 month ago
CRITICALGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

1 month ago
HIGHGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

1 month ago
HIGHGo

New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API: Integer overflow in quota billing yields negative charges (self-crediting)

1 month ago
MODERATEGo

New API: Admin can reset passkeys for same-level or higher-privileged users

New API: Admin can reset passkeys for same-level or higher-privileged users

github.com/QuantumNous/new-api: 0.9.1.3 → 1.0.0-rc.7

1 month ago
MODERATEGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

1 month ago
MODERATEGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

1 month ago
CRITICALGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

1 month ago
UNKNOWNGo

Excessive memory allocation during VP8L decoding in golang.org/x/image

Excessive memory allocation during VP8L decoding in golang.org/x/image

1 month ago
MODERATEGo

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

1 month ago
CRITICALGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

1 month ago
HIGHGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

1 month ago
UNKNOWNGo

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

1 month ago
UNKNOWNGo

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

1 month ago
UNKNOWNGo

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

1 month ago
UNKNOWNGo

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

1 month ago
HIGHGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

1 month ago
UNKNOWNGo

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

1 month ago
UNKNOWNGo

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

1 month ago
UNKNOWNGo

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

1 month ago
UNKNOWNGo

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

1 month ago
HIGHGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

1 month ago
HIGHGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

1 month ago
UNKNOWNGo

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

1 month ago
UNKNOWNGo

Unauthenticated backend instantiation in github.com/rclone/rclone

Unauthenticated backend instantiation in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

1 month ago
UNKNOWNGo

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

1 month ago
UNKNOWNGo

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

1 month ago
UNKNOWNGo

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

1 month ago
UNKNOWNGo

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

1 month ago
HIGHGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

1 month ago
UNKNOWNGo

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

1 month ago
HIGHGo

go-git: Malicious reference names may modify files outside the reference storage

go-git: Malicious reference names may modify files outside the reference storage

1 month ago
HIGHGo

go-git: Worktree operations may follow symlinks

go-git: Worktree operations may follow symlinks

1 month ago
MODERATEGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

2 months ago
HIGHGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

2 months ago
HIGHGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

2 months ago
HIGHGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

2 months ago
HIGHGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

2 months ago
MEDIUMGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

2 months ago
HIGHGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

2 months ago
LOWGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

2 months ago
MODERATEGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

2 months ago
CRITICALGo

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

2 months ago
HIGHGo

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

2 months ago
HIGHGo

rclone: Incomplete path validation allows backend root escape in serve restic

rclone: Incomplete path validation allows backend root escape in serve restic

2 months ago
HIGHGo

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

2 months ago
HIGHGo

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

2 months ago
MEDIUMGo

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

2 months ago
CRITICALGo

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

2 months ago
HIGHGo

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

2 months ago
MEDIUMGo

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

2 months ago
HIGHGo

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

2 months ago
MEDIUMGo

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

2 months ago
MEDIUMGo

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

2 months ago
MEDIUMGo

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

2 months ago
HIGHGo

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

2 months ago
MODERATEGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

2 months ago
HIGHGo

rclone: Local Encoding Path Traversal

rclone: Local Encoding Path Traversal

2 months ago
MODERATEGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

2 months ago
MEDIUMGo

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

2 months agoEPSS 0%
MEDIUMGo

sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go fails to check signature timestamps against a signing key's validity period

2 months agoEPSS 0%
MODERATEGo

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

2 months agoEPSS 0%
HIGHGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

2 months agoEPSS 0%
HIGHGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

2 months agoEPSS 0%
HIGHGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

2 months agoEPSS 0%
HIGHGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

2 months agoEPSS 0%
HIGHGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

2 months agoEPSS 0%
MEDIUMGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

2 months agoEPSS 0%
MODERATEGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

2 months agoEPSS 0%
CRITICALGo

Wings exposes node configuration secrets through egg configuration-file templating

Wings exposes node configuration secrets through egg configuration-file templating

2 months agoEPSS 0%
CRITICALGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

2 months agoEPSS 1%
MEDIUMGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

2 months agoEPSS 0%
HIGHGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

2 months agoEPSS 0%
HIGHGo

netfoil: Incorrect block responses could lead to localhost traffic

netfoil: Incorrect block responses could lead to localhost traffic

2 months ago
HIGHGo

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

2 months agoEPSS 0%
CRITICALGo

Logging operator has Fluentd configuration injection that allows remote code execution

Logging operator has Fluentd configuration injection that allows remote code execution

2 months agoEPSS 0%
CRITICALGo

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

2 months agoEPSS 0%
MODERATEGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

2 months agoEPSS 0%
MEDIUMGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

2 months ago
MODERATEGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

2 months agoEPSS 0%
MEDIUMGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

2 months ago
HIGHGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

2 months ago
HIGHGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

2 months ago
HIGHGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

2 months ago
HIGHGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

2 months ago
HIGHGo

openhole-server vulnerable to path traversal via URL-decoded request path

openhole-server vulnerable to path traversal via URL-decoded request path

2 months ago
HIGHGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

2 months ago
HIGHGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

2 months ago
HIGHGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

2 months ago
MEDIUMGo

goshs has a Path Traversal issue

goshs has a Path Traversal issue

2 months ago
MEDIUMGo

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

2 months ago
HIGHGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

2 months ago
MEDIUMGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

2 months ago
MODERATEGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

2 months ago
HIGHGo

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

2 months ago
UNKNOWNGo

OOB read in github.com/klauspost/compress/s2

OOB read in github.com/klauspost/compress/s2

2 months ago
UNKNOWNGo

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

2 months agoEPSS 0%
UNKNOWNGo

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

2 months ago
UNKNOWNGo

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

2 months ago
UNKNOWNGo

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

2 months ago
HIGHGo

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

2 months ago
UNKNOWNGo

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

2 months ago
UNKNOWNGo

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

2 months ago
UNKNOWNGo

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

2 months ago
CRITICALGo

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

2 months ago
UNKNOWNGo

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

2 months ago
UNKNOWNGo

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

2 months ago
UNKNOWNGo

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

2 months ago
MEDIUMGo

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

2 months ago
UNKNOWNGo

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

2 months ago
HIGHGo

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

2 months ago
UNKNOWNGo

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

2 months ago
HIGHGo

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

2 months ago
MEDIUMGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

2 months ago
HIGHGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

2 months ago
MODERATEGo

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

2 months ago
MEDIUMGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

2 months ago
MEDIUMGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

2 months ago
UNKNOWNGo

Hardlink path traversal during tar extraction in oras.land/oras-go

Hardlink path traversal during tar extraction in oras.land/oras-go

2 months agoEPSS 0%
HIGHGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

2 months ago
HIGHGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

2 months ago
UNKNOWNGo

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

2 months ago
HIGHGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

2 months ago
HIGHGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

2 months ago
UNKNOWNGo

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

2 months ago
MEDIUMGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

2 months ago
HIGHGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

2 months ago
MEDIUMGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

2 months ago
MEDIUMGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

2 months ago
MEDIUMGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

2 months ago
UNKNOWNGo

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

2 months ago
UNKNOWNGo

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

2 months ago
UNKNOWNGo

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

2 months ago
UNKNOWNGo

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

2 months ago
HIGHGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

2 months ago
UNKNOWNGo

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

2 months agoEPSS 0%
UNKNOWNGo

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper

2 months ago
UNKNOWNGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

2 months ago
UNKNOWNGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

2 months ago
UNKNOWNGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

2 months ago
UNKNOWNGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

2 months ago
MODERATEGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

2 months ago
HIGHGo

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

2 months ago
HIGHGo

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

2 months ago
HIGHGo

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

2 months ago
LOWGo

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

2 months ago
UNKNOWNGo

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

2 months ago
MODERATEGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

2 months ago
MODERATEGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured

kumactl connects to control plane without verifying TLS certificate when no CA is configured

2 months ago
HIGHGo

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

2 months ago
HIGHGo

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

2 months ago
HIGHGo

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

2 months ago
HIGHGo

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

2 months ago
HIGHGo

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

2 months ago
HIGHGo

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

2 months ago
HIGHGo

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

2 months ago
HIGHGo

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

2 months agoEPSS 0%
UNKNOWNGo

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

2 months ago
UNKNOWNGo

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

2 months ago
HIGHGo

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

2 months ago
HIGHGo

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

2 months ago
HIGHGo

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

2 months ago
CRITICALGo

melange: Incomplete package integrity verification allows data section substitution

melange: Incomplete package integrity verification allows data section substitution

2 months ago
HIGHGo

sigstore-go has a multi-log threshold bypass via single compromised log

sigstore-go has a multi-log threshold bypass via single compromised log

2 months agoEPSS 0%
HIGHGo

GoBGP confederation validation panics on empty AS_PATH attribute

GoBGP confederation validation panics on empty AS_PATH attribute

2 months ago
UNKNOWNGo

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour

3 months ago
UNKNOWNGo

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

3 months ago
UNKNOWNGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

3 months ago
UNKNOWNGo

Root escape via symlink plus trailing slash in os

Root escape via symlink plus trailing slash in os

3 months ago
UNKNOWNGo

Concourse login flow has an open redirect issue in github.com/concourse/concourse

Concourse login flow has an open redirect issue in github.com/concourse/concourse

3 months ago
UNKNOWNGo

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

3 months ago
HIGHGo

KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

3 months ago
HIGHGo

LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs

LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs

3 months ago
UNKNOWNGo

Invoking Encrypted Client Hello privacy leak in crypto/tls

Invoking Encrypted Client Hello privacy leak in crypto/tls

3 months agoEPSS 0%
HIGHGo

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

3 months ago
HIGHGo

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

3 months ago
CRITICALGo

Gitea LFS mirror operations bypass migration HTTP transport protections

Gitea LFS mirror operations bypass migration HTTP transport protections

3 months ago
HIGHGo

Gitea OAuth2 PKCE S256 verifier bypass

Gitea OAuth2 PKCE S256 verifier bypass

3 months ago
HIGHGo

Gitea template repository generation follows unsafe filesystem paths

Gitea template repository generation follows unsafe filesystem paths

3 months ago
HIGHGo

Gitea git grep searches allow server resource exhaustion

Gitea git grep searches allow server resource exhaustion

3 months ago
HIGHGo

Gitea organization permission APIs expose hidden membership and private organization data

Gitea organization permission APIs expose hidden membership and private organization data

3 months ago
HIGHGo

Gitea primary email ownership bypass allows cross-user email changes

Gitea primary email ownership bypass allows cross-user email changes

3 months ago
HIGHGo

Gitea repository creation accepts insufficiently validated fields

Gitea repository creation accepts insufficiently validated fields

3 months ago
MEDIUMGo

Gitea release asset dumps permit path traversal through crafted names

Gitea release asset dumps permit path traversal through crafted names

3 months ago
HIGHGo

Gitea OAuth2 authorization codes can be reused after expiry

Gitea OAuth2 authorization codes can be reused after expiry

3 months ago
HIGHGo

Gitea pull request branch permission checks allow unauthorized updates and rebases

Gitea pull request branch permission checks allow unauthorized updates and rebases

3 months ago
MEDIUMGo

Gitea exposes tracked time entries without repository authorization

Gitea exposes tracked time entries without repository authorization

3 months ago
MEDIUMGo

Gitea tracked-time deletion is not scoped to the requested issue

Gitea tracked-time deletion is not scoped to the requested issue

3 months ago
HIGHGo

Gitea draft releases and attachments are exposed without write permission

Gitea draft releases and attachments are exposed without write permission

3 months ago
CRITICALGo

Gitea pre-receive hook scanner errors allow branch-protection bypass

Gitea pre-receive hook scanner errors allow branch-protection bypass

3 months ago
HIGHGo

Gitea forwarded-proto validation allows canonical URL spoofing

Gitea forwarded-proto validation allows canonical URL spoofing

3 months ago
HIGHGo

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

3 months ago
HIGHGo

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

3 months ago
MEDIUMGo

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

3 months agoEPSS 0%
LOWGo

Concourse login flow has an open redirect issue

Concourse login flow has an open redirect issue

3 months ago
CRITICALGo

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

3 months ago
CRITICALGo

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

3 months ago
LOWGo

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

3 months ago
MODERATEGo

oras-go has file store write outside workingDir via symlink traversal

oras-go has file store write outside workingDir via symlink traversal

3 months ago
CRITICALGo

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

3 months ago
MODERATEGo

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

3 months ago
HIGHGo

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

3 months ago
MEDIUMGo

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

3 months ago
HIGHGo

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

3 months agoEPSS 0%
MODERATEGo

fzf vulnerable to denial of service through quadratic HTTP request-body accumulation

fzf vulnerable to denial of service through quadratic HTTP request-body accumulation

3 months ago
HIGHGo

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

3 months ago
HIGHGo

Nightingale exposes datasource credentials to low-privilege users

Nightingale exposes datasource credentials to low-privilege users

3 months ago
HIGHGo

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

3 months ago
HIGHGo

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

3 months ago
CRITICALGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

3 months ago
HIGHGo

regclient may leak authentication credentials to external blob stores

regclient may leak authentication credentials to external blob stores

3 months ago
UNKNOWNGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

3 months ago
UNKNOWNGo

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0

3 months ago
MEDIUMGo

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

3 months ago
UNKNOWNGo

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0

3 months ago
MODERATEGo

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

3 months ago
UNKNOWNGo

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

3 months ago
HIGHGo

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

3 months ago
MEDIUMGo

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

3 months agoEPSS 1%
HIGHGo

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

3 months agoEPSS 1%
UNKNOWNGo

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

3 months ago
HIGHGo

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

3 months ago
UNKNOWNGo

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0

3 months ago
HIGHGo

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto vulnerable to infinite loop on large channel writes

3 months ago
UNKNOWNGo

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0

3 months ago
MEDIUMGo

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

3 months ago
HIGHGo

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

3 months ago
HIGHGo

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

3 months ago
HIGHGo

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

3 months ago
UNKNOWNGo

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0

3 months ago
HIGHGo

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

3 months ago
UNKNOWNGo

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0

3 months ago
UNKNOWNGo

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0

3 months ago
UNKNOWNGo

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0

3 months ago
HIGHGo

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

3 months ago
HIGHGo

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

3 months agoEPSS 1%
UNKNOWNGo

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0

3 months ago
UNKNOWNGo

Authenticate method auth bypass in github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension

Authenticate method auth bypass in github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension

3 months ago
UNKNOWNGo

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0

3 months ago
UNKNOWNGo

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0

3 months ago
HIGHGo

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

3 months ago
UNKNOWNGo

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

3 months ago
UNKNOWNGo

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

3 months ago
HIGHGo

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto doesn't enforce invoking key constraints

3 months ago
UNKNOWNGo

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

3 months ago
UNKNOWNGo

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno

3 months ago
UNKNOWNGo

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0

3 months ago
UNKNOWNGo

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0

3 months ago
HIGHGo

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

3 months ago
UNKNOWNGo

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation

3 months ago
UNKNOWNGo

Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0

Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0

3 months ago
HIGHGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

3 months ago
HIGHGo

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

3 months ago
HIGHGo

OpenShift Cluster Logging Operator missing authorization flaw

OpenShift Cluster Logging Operator missing authorization flaw

3 months ago
MEDIUMGo

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

3 months ago
HIGHGo

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

3 months ago
HIGHGo

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

3 months ago
MEDIUMGo

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

3 months ago
MEDIUMGo

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

3 months ago
MEDIUMGo

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

3 months ago
HIGHGo

Gophish contains a denial of service vulnerability

Gophish contains a denial of service vulnerability

3 months ago
MEDIUMGo

Mattermost has an Incorrect Authorization issue

Mattermost has an Incorrect Authorization issue

3 months ago
HIGHGo

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

3 months ago
HIGHGo

containerd CRI checkpoint restore CDI annotation smuggling

containerd CRI checkpoint restore CDI annotation smuggling

3 months ago
HIGHGo

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

3 months ago
HIGHGo

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

3 months ago
MODERATEGo

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

3 months ago
CRITICALGo

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

3 months ago
MEDIUMGo

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

3 months ago
HIGHGo

Grafana Tempo vulnerable to an out-of-memory crash

Grafana Tempo vulnerable to an out-of-memory crash

3 months ago
CRITICALGo

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

3 months ago
HIGHGo

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

3 months ago
MEDIUMGo

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

3 months ago
HIGHGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

3 months ago
HIGHGo

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

3 months ago
CRITICALGo

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

3 months ago
HIGHGo

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

3 months ago
HIGHGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

3 months ago
HIGHGo

Filestash allows attackers to escalate privileges via sending a crafted request

Filestash allows attackers to escalate privileges via sending a crafted request

3 months ago
HIGHGo

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request

3 months ago
CRITICALGo

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

3 months ago
CRITICALGo

MCP Toolbox for Databases has an Origin Validation Error

MCP Toolbox for Databases has an Origin Validation Error

3 months ago
MEDIUMGo

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

3 months ago
HIGHGo

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

3 months ago
HIGHGo

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

3 months ago
CRITICALGo

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

3 months ago
HIGHGo

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

3 months ago
HIGHGo

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

3 months ago
MEDIUMGo

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

3 months ago
HIGHGo

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

3 months ago
MEDIUMGo

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

3 months ago
HIGHGo

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

3 months ago
HIGHGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

3 months ago
HIGHGo

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

3 months ago
CRITICALGo

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

3 months ago
CRITICALGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

3 months ago
HIGHGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

3 months ago
HIGHGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

3 months ago
HIGHGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

3 months ago
HIGHGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

3 months ago
HIGHGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

3 months agoEPSS 0%
HIGHGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

3 months agoEPSS 0%
MEDIUMGo

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

3 months agoEPSS 0%
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

3 months ago
MEDIUMGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

3 months ago
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

3 months ago
MEDIUMGo

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

4 months ago
MEDIUMGo

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

4 months ago
UNKNOWNGo

Inefficient candidate hostname parsing in crypto/x509

Inefficient candidate hostname parsing in crypto/x509

4 months agoEPSS 1%
UNKNOWNGo

Arbitrary inputs are included in errors without any escaping in net/textproto

Arbitrary inputs are included in errors without any escaping in net/textproto

4 months agoEPSS 0%
UNKNOWNGo

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

4 months agoEPSS 1%
HIGHGo

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

4 months ago
MEDIUMGo

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

4 months ago
HIGHGo

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

4 months ago
HIGHGo

go-git: Malformed Git object data may cause panics or resource exhaustion

go-git: Malformed Git object data may cause panics or resource exhaustion

4 months ago
MEDIUMGo

opentelemetry-go's baggage parsing no longer caps raw header length

opentelemetry-go's baggage parsing no longer caps raw header length

4 months ago
HIGHGo

KubeVirt has a Link Following issue

KubeVirt has a Link Following issue

4 months ago
HIGHGo

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

4 months ago
HIGHGo

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

4 months ago
CRITICALGo

KubeVirt has a Link Following vulnerability

KubeVirt has a Link Following vulnerability

4 months ago
HIGHGo

Go Net HTML parser is vulnerable to denial of service

Go Net HTML parser is vulnerable to denial of service

4 months ago
UNKNOWNGo

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

4 months ago
UNKNOWNGo

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

4 months ago
UNKNOWNGo

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

4 months ago
UNKNOWNGo

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

4 months ago
UNKNOWNGo

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

4 months ago
UNKNOWNGo

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

4 months ago
UNKNOWNGo

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

4 months ago
UNKNOWNGo

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

4 months ago
UNKNOWNGo

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

4 months ago
UNKNOWNGo

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

4 months ago
UNKNOWNGo

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

4 months ago
UNKNOWNGo

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

4 months ago
CRITICALGo

containerd user ID handling bypass allows runAsNonRoot evasion

containerd user ID handling bypass allows runAsNonRoot evasion

4 months ago
UNKNOWNGo

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

4 months ago
MEDIUMGo

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

4 months ago
HIGHGo

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

4 months ago
MEDIUMGo

MCP Registry: OCI validator skips ownership check on upstream rate limits

MCP Registry: OCI validator skips ownership check on upstream rate limits

4 months ago
HIGHGo

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

4 months ago
HIGHGo

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

4 months ago
LOWGo

go-git: Improper single-quote escaping in go-git SSH transport

go-git: Improper single-quote escaping in go-git SSH transport

4 months ago
MEDIUMGo

go-git: Crafted repositories may modify main and submodule .git directories

go-git: Crafted repositories may modify main and submodule .git directories

4 months ago
HIGHGo

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

4 months ago
HIGHGo

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

4 months ago
HIGHGo

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

4 months ago
MEDIUMGo

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

4 months ago
HIGHGo

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

4 months ago
HIGHGo

iskorotkov/avro: Integer Overflow in Decoder

iskorotkov/avro: Integer Overflow in Decoder

4 months ago
HIGHGo

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

4 months ago
HIGHGo

Docker: `PUT /containers/{id}/archive` executes container binary on the host

Docker: `PUT /containers/{id}/archive` executes container binary on the host

4 months ago
HIGHGo

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

4 months ago
HIGHGo

Docker: Race condition in docker cp allows bind mount redirection to host path

Docker: Race condition in docker cp allows bind mount redirection to host path

4 months ago
HIGHGo

iskorotkov/avro: CPU Exhaustion in Decoder

iskorotkov/avro: CPU Exhaustion in Decoder

4 months ago
MODERATEGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

4 months ago
HIGHGo

go-billy has path traversal vulnerabilities

go-billy has path traversal vulnerabilities

4 months ago
MODERATEGo

slack-go `SecretsVerifier` accepts empty signing secret without precondition

slack-go `SecretsVerifier` accepts empty signing secret without precondition

4 months ago
HIGHGo

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

4 months ago
HIGHGo

Grafana: SQL Expressions Read File From Disk

Grafana: SQL Expressions Read File From Disk

4 months ago
HIGHGo

Grafana: Users can generate Service Account tokens after permissions removal

Grafana: Users can generate Service Account tokens after permissions removal

4 months ago
HIGHGo

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

4 months ago
CRITICALGo

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

4 months ago
MEDIUMGo

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience

5 months ago

Tooling for Go

Snyk — Scan your dependencies in CI and fix this vulnerability.→

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionshexMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm