Go incidents

Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MEDIUMGo

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

4 days ago
MEDIUMGo

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

4 days ago
UNKNOWNGo

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost

5 days ago
UNKNOWNGo

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium

5 days ago
UNKNOWNGo

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

5 days ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo

5 days ago
UNKNOWNGo

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit

5 days ago
UNKNOWNGo

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore

Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore

5 days ago
UNKNOWNGo

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo

5 days ago
UNKNOWNGo

Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

5 days ago
CRITICALGo

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

5 days ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
MODERATEGo

Traefik: ForwardAuth identity spoofing via dot-form header alias

Traefik: ForwardAuth identity spoofing via dot-form header alias

5 days ago
UNKNOWNGo

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

5 days ago
UNKNOWNGo

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs

5 days ago
UNKNOWNGo

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

5 days ago
UNKNOWNGo

ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf

ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf

5 days ago
UNKNOWNGo

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone: S3 multipart declared-length memory exhaustion

rclone: S3 multipart declared-length memory exhaustion

5 days ago
UNKNOWNGo

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone: RC per-server auth-proxy bypass

rclone: RC per-server auth-proxy bypass

5 days ago
UNKNOWNGo

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

5 days ago
MEDIUMGo

rclone: http backend forwards custom/auth headers to a different host on redirect

rclone: http backend forwards custom/auth headers to a different host on redirect

5 days ago
UNKNOWNGo

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

5 days ago
UNKNOWNGo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo

5 days ago
UNKNOWNGo

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

Traefik entrypoint header-name sanitization bypassed via request trailers

Traefik entrypoint header-name sanitization bypassed via request trailers

5 days ago
UNKNOWNGo

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone: source object names can escape the configured root on upload

rclone: source object names can escape the configured root on upload

5 days ago
UNKNOWNGo

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

5 days ago
HIGHGo

rclone: FTP cross-session auth-proxy backend confusion

rclone: FTP cross-session auth-proxy backend confusion

5 days ago
UNKNOWNGo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

5 days ago
HIGHGo

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

5 days ago
UNKNOWNGo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo

5 days ago
UNKNOWNGo

Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

5 days ago
UNKNOWNGo

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
CRITICALGo

Traefik HTTP/3 Backend NTLM Connection Reuse

Traefik HTTP/3 Backend NTLM Connection Reuse

5 days ago
MEDIUMGo

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

5 days ago
UNKNOWNGo

Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost

Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost

5 days ago
UNKNOWNGo

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore

5 days ago
UNKNOWNGo

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

5 days ago
UNKNOWNGo

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit

5 days ago
UNKNOWNGo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo

5 days ago
UNKNOWNGo

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore

5 days ago
UNKNOWNGo

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox

5 days ago
UNKNOWNGo

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel

5 days ago
MEDIUMGo

rclone local: crafted Range request against a translated symlink panics (DoS)

rclone local: crafted Range request against a translated symlink panics (DoS)

5 days ago
UNKNOWNGo

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel

5 days ago
UNKNOWNGo

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

5 days ago
HIGHGo

Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

5 days ago
UNKNOWNGo

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle

5 days ago
MODERATEGo

Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

5 days ago
UNKNOWNGo

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList

5 days ago
CRITICALGo

Komari: Management Interface CSRF

Komari: Management Interface CSRF

6 days ago
MODERATEGo

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

6 days ago
MEDIUMGo

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

6 days ago
UNKNOWNGo

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

6 days ago
HIGHGo

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

6 days ago
MEDIUMGo

webhookd: Unrestricted HTTP Header to Shell Variable Injection

webhookd: Unrestricted HTTP Header to Shell Variable Injection

6 days ago
HIGHGo

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

6 days ago
HIGHGo

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

6 days ago
CRITICALGo

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

6 days ago
MODERATEGo

Infracost: Arbitrary file read via config-template readFile symlink traversal

Infracost: Arbitrary file read via config-template readFile symlink traversal

1 week ago
HIGHGo

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

1 week ago
CRITICALGo

Semaphore U: OS Command Injection

Semaphore U: OS Command Injection

1 week ago
MODERATEGo

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

1 week ago
LOWGo

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

1 week ago
MEDIUMGo

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

1 week ago
MEDIUMGo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

1 week ago
CRITICALGo

Gitea: Remote Code Execution via diffpatch Git Hook Installation

Gitea: Remote Code Execution via diffpatch Git Hook Installation

1 week ago
HIGHGo

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

1 week ago
MODERATEGo

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

1 week ago
MEDIUMGo

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

1 week ago
MEDIUMGo

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

1 week ago
MEDIUMGo

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers

SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers

1 week ago
HIGHGo

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

1 week ago
HIGHGo

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

1 week ago
CRITICALGo

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

1 week ago
MEDIUMGo

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

1 week ago
HIGHGo

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

1 week ago
HIGHGo

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers

1 week ago
MEDIUMGo

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

1 week ago
HIGHGo

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

1 week ago
MEDIUMGo

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

1 week ago
HIGHGo

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

1 week ago
MEDIUMGo

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

1 week ago
HIGHGo

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

1 week ago
HIGHGo

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

1 week ago
HIGHGo

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

1 week ago
HIGHGo

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

1 week ago
CRITICALGo

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

1 week ago
HIGHGo

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

1 week ago
HIGHGo

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

1 week ago
HIGHGo

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

1 week ago
MEDIUMGo

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

1 week ago
MEDIUMGo

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

1 week ago
HIGHGo

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

1 week ago
MEDIUMGo

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

1 week ago
HIGHGo

ffuf denial of service (OOM) via HTTP response decompression bomb

ffuf denial of service (OOM) via HTTP response decompression bomb

1 week ago
MEDIUMGo

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

1 week ago
HIGHGo

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

1 week ago
MEDIUMGo

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

1 week ago
HIGHGo

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

1 week ago
HIGHGo

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

1 week ago
HIGHGo

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

1 week ago
HIGHGo

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

1 week ago
MEDIUMGo

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

1 week ago
HIGHGo

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

1 week ago
HIGHGo

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

1 week ago
UNKNOWNGo

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf

1 week ago
UNKNOWNGo

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs

1 week ago
HIGHGo

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

1 week ago
UNKNOWNGo

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api

1 week ago
UNKNOWNGo

Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo

Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo

1 week ago
UNKNOWNGo

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api

1 week ago
HIGHGo

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection

1 week ago
UNKNOWNGo

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer

1 week ago
UNKNOWNGo

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf

1 week ago
UNKNOWNGo

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet

1 week ago
UNKNOWNGo

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api

1 week ago
UNKNOWNGo

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs

1 week ago
UNKNOWNGo

KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela

KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela

1 week ago
UNKNOWNGo

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

1 week ago
UNKNOWNGo

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend

1 week ago
UNKNOWNGo

Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea

Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea

Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea

1 week ago
CRITICALGo

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

1 week ago
UNKNOWNGo

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua

1 week ago
UNKNOWNGo

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc

1 week ago
UNKNOWNGo

Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api

Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api

1 week ago
UNKNOWNGo

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api

1 week ago
UNKNOWNGo

Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea

Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea

Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

1 week ago
UNKNOWNGo

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go

1 week ago
UNKNOWNGo

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras

1 week ago
UNKNOWNGo

Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus

Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus

1 week ago
UNKNOWNGo

Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea

Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea

Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea

Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea

1 week ago
CRITICALGo

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

1 week ago
UNKNOWNGo

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http

1 week ago
HIGHGo

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling

1 week ago
UNKNOWNGo

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc

1 week ago
UNKNOWNGo

Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus

Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus

1 week ago
CRITICALGo

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

1 week ago
HIGHGo

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

1 week ago
UNKNOWNGo

Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea

Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea

1 week ago
UNKNOWNGo

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core

1 week ago
UNKNOWNGo

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go

1 week ago
UNKNOWNGo

Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea

Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea

1 week ago
HIGHGo

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

1 week ago
UNKNOWNGo

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go

1 week ago
MEDIUMGo

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

1 week ago
CRITICALGo

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

1 week ago
UNKNOWNGo

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go

1 week ago
UNKNOWNGo

Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea

Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea

1 week ago
HIGHGo

Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends

Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends

1 week ago
HIGHGo

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

2 weeks ago
MEDIUMGo

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

2 weeks ago
MEDIUMGo

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption

ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption

2 weeks ago
CRITICALGo

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints

free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints

2 weeks ago
MEDIUMGo

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe

Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe

2 weeks ago
HIGHGo

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

2 weeks ago
MEDIUMGo

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0

2 weeks ago
HIGHGo

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory

Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory

2 weeks ago
HIGHGo

Incus has a project restriction bypass for custom volume copy across projects

Incus has a project restriction bypass for custom volume copy across projects

2 weeks ago
HIGHGo

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key

2 weeks ago
MODERATEGo

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset

arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset

2 weeks ago
HIGHGo

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI

2 weeks ago
HIGHGo

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id

Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id

2 weeks ago
HIGHGo

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)

Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)

2 weeks ago
HIGHGo

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

2 weeks ago
HIGHGo

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

2 weeks ago
MODERATEGo

Vikunja has a project duplication bypasses write-permission check on the target parent project

Vikunja has a project duplication bypasses write-permission check on the target parent project

2 weeks ago
HIGHGo

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)

2 weeks ago
HIGHGo

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

2 weeks ago
MEDIUMGo

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment

Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment

2 weeks ago
MEDIUMGo

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none

2 weeks ago
HIGHGo

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL

2 weeks ago
UNKNOWNGo

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

2 weeks ago
HIGHGo

KubeVela Terraform remote loader DoS via unbounded file read

KubeVela Terraform remote loader DoS via unbounded file read

2 weeks ago
MEDIUMGo

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

2 weeks ago
HIGHGo

Incus has a project restriction bypass in instance copy across projects

Incus has a project restriction bypass in instance copy across projects

2 weeks ago
HIGHGo

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

2 weeks ago
UNKNOWNGo

Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash

Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash

2 weeks ago
LOWGo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

2 weeks ago
UNKNOWNGo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo

2 weeks ago
UNKNOWNGo

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno

2 weeks ago
UNKNOWNGo

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server

2 weeks ago
HIGHGo

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

2 weeks ago
UNKNOWNGo

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng

2 weeks ago
UNKNOWNGo

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

2 weeks ago
UNKNOWNGo

Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5

Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5

2 weeks ago
HIGHGo

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

2 weeks ago
HIGHGo

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system

Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system

2 weeks ago
UNKNOWNGo

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy

2 weeks ago
UNKNOWNGo

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp

2 weeks ago
UNKNOWNGo

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell

2 weeks ago
UNKNOWNGo

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell

2 weeks ago
UNKNOWNGo

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell

2 weeks ago
UNKNOWNGo

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget

3 weeks ago
CRITICALGo

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias

mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias

3 weeks ago
UNKNOWNGo

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil

3 weeks ago
UNKNOWNGo

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi

3 weeks ago
UNKNOWNGo

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket

3 weeks ago
HIGHGo

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files

3 weeks ago
UNKNOWNGo

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy

3 weeks ago
UNKNOWNGo

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

3 weeks ago
UNKNOWNGo

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy

3 weeks ago
UNKNOWNGo

moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive

moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive

3 weeks ago
UNKNOWNGo

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit

3 weeks ago
HIGHGo

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

3 weeks ago
UNKNOWNGo

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

3 weeks ago
UNKNOWNGo

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing

3 weeks ago
UNKNOWNGo

Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero

Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero

3 weeks ago
UNKNOWNGo

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code

3 weeks ago
UNKNOWNGo

BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit

BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit

3 weeks ago
UNKNOWNGo

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember

3 weeks ago
UNKNOWNGo

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

3 weeks ago
UNKNOWNGo

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

3 weeks ago
HIGHGo

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

3 weeks ago
CRITICALGo

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

3 weeks ago
HIGHGo

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport

genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport

3 weeks ago
UNKNOWNGo

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet

3 weeks ago
UNKNOWNGo

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis

3 weeks ago
UNKNOWNGo

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet

3 weeks ago
UNKNOWNGo

BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit

BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit

3 weeks ago
UNKNOWNGo

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit

3 weeks ago
UNKNOWNGo

MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox

MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox

3 weeks ago
UNKNOWNGo

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

3 weeks ago
UNKNOWNGo

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

3 weeks ago
UNKNOWNGo

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph

3 weeks ago
UNKNOWNGo

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu

3 weeks ago
UNKNOWNGo

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi

3 weeks ago
UNKNOWNGo

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code

3 weeks ago
UNKNOWNGo

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

3 weeks ago
UNKNOWNGo

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet

3 weeks ago
MODERATEGo

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

3 weeks ago
CRITICALGo

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3 weeks ago
MEDIUMGo

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

3 weeks ago
LOWGo

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

3 weeks ago
MODERATEGo

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

3 weeks ago
HIGHGo

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

3 weeks ago
HIGHGo

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

3 weeks ago
HIGHGo

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

3 weeks ago
MEDIUMGo

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

3 weeks ago
HIGHGo

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

3 weeks ago
MEDIUMGo

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

3 weeks ago
HIGHGo

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

3 weeks ago
HIGHGo

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

3 weeks ago
MODERATEGo

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

3 weeks ago
HIGHGo

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

3 weeks ago
MEDIUMGo

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

3 weeks ago
MEDIUMGo

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

3 weeks ago
HIGHGo

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

3 weeks ago
MODERATEGo

Velero vulnerable to file path traversal when extracting from backup's tarball

Velero vulnerable to file path traversal when extracting from backup's tarball

3 weeks ago
MEDIUMGo

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

3 weeks ago
MEDIUMGo

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

3 weeks ago
MEDIUMGo

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

3 weeks ago
HIGHGo

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

3 weeks ago
UNKNOWNGo

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

3 weeks ago
MODERATEGo

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

3 weeks ago
LOWGo

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

3 weeks ago
MODERATEGo

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

3 weeks ago
UNKNOWNGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

4 weeks ago
UNKNOWNGo

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

4 weeks ago
UNKNOWNGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

4 weeks ago
UNKNOWNGo

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

4 weeks ago
UNKNOWNGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

goshs has a Path Traversal issue in github.com/patrickhener/goshs

goshs has a Path Traversal issue in github.com/patrickhener/goshs

4 weeks ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

4 weeks ago
UNKNOWNGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

4 weeks ago
UNKNOWNGo

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

4 weeks ago
UNKNOWNGo

Watch API authorization bypass in go.etcd.io/etcd/server/v3

Watch API authorization bypass in go.etcd.io/etcd/server/v3

4 weeks ago
UNKNOWNGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

4 weeks ago
UNKNOWNGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

4 weeks ago
UNKNOWNGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

4 weeks ago
UNKNOWNGo

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

4 weeks ago
UNKNOWNGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

4 weeks ago
UNKNOWNGo

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

4 weeks ago
UNKNOWNGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

4 weeks ago
UNKNOWNGo

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

4 weeks ago
UNKNOWNGo

Integer overflow in BTF parsing in github.com/cilium/ebpf

Integer overflow in BTF parsing in github.com/cilium/ebpf

4 weeks ago
UNKNOWNGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

4 weeks ago
UNKNOWNGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

4 weeks ago
UNKNOWNGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

4 weeks ago
UNKNOWNGo

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

4 weeks ago
UNKNOWNGo

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

4 weeks ago
UNKNOWNGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

4 weeks ago
UNKNOWNGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

4 weeks ago
UNKNOWNGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

4 weeks ago
UNKNOWNGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

4 weeks ago
UNKNOWNGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

4 weeks ago
UNKNOWNGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

4 weeks ago
UNKNOWNGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

4 weeks ago
UNKNOWNGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

4 weeks ago
UNKNOWNGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

4 weeks ago
UNKNOWNGo

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

4 weeks ago
UNKNOWNGo

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

4 weeks ago
UNKNOWNGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

4 weeks ago
UNKNOWNGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

4 weeks ago
UNKNOWNGo

Path traversal in serve s3 in github.com/rclone/rclone

Path traversal in serve s3 in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

4 weeks ago
UNKNOWNGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

4 weeks ago
UNKNOWNGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

4 weeks ago
UNKNOWNGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

4 weeks ago
UNKNOWNGo

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

4 weeks ago
UNKNOWNGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

4 weeks ago
UNKNOWNGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

4 weeks ago
UNKNOWNGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

4 weeks ago
UNKNOWNGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

4 weeks ago
UNKNOWNGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

4 weeks ago
UNKNOWNGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

4 weeks ago
UNKNOWNGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

4 weeks ago
UNKNOWNGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

4 weeks ago
UNKNOWNGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

4 weeks ago
UNKNOWNGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

4 weeks ago
UNKNOWNGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

4 weeks ago
UNKNOWNGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

4 weeks ago
UNKNOWNGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

4 weeks ago
UNKNOWNGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

4 weeks ago
UNKNOWNGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

4 weeks ago
UNKNOWNGo

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

4 weeks ago
UNKNOWNGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

4 weeks ago
UNKNOWNGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

4 weeks ago
UNKNOWNGo

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

4 weeks ago
UNKNOWNGo

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

4 weeks ago
UNKNOWNGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

4 weeks ago
UNKNOWNGo

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

4 weeks ago
UNKNOWNGo

Path traversal via crafted reference names in github.com/go-git/go-git

Path traversal via crafted reference names in github.com/go-git/go-git

4 weeks ago
UNKNOWNGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

4 weeks ago
UNKNOWNGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

4 weeks ago
UNKNOWNGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

4 weeks ago
MEDIUMGo

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

4 weeks ago
UNKNOWNGo

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

4 weeks ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

4 weeks ago
UNKNOWNGo

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

4 weeks ago
UNKNOWNGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

4 weeks ago
MODERATEGo

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

4 weeks ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

4 weeks ago
UNKNOWNGo

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

4 weeks ago
UNKNOWNGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

4 weeks ago
UNKNOWNGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

4 weeks ago
UNKNOWNGo

Worktree operations may follow symlinks in github.com/go-git/go-git

Worktree operations may follow symlinks in github.com/go-git/go-git

4 weeks ago
UNKNOWNGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

4 weeks ago
UNKNOWNGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

4 weeks ago
UNKNOWNGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

4 weeks ago
UNKNOWNGo

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

4 weeks ago
HIGHGo

moby/go-archive: Crafted tar archive can write outside the extraction directory

moby/go-archive: Crafted tar archive can write outside the extraction directory

4 weeks ago
UNKNOWNGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

4 weeks ago
UNKNOWNGo

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

4 weeks ago
UNKNOWNGo

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

4 weeks ago
UNKNOWNGo

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

4 weeks ago
UNKNOWNGo

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

4 weeks ago
UNKNOWNGo

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

4 weeks ago
UNKNOWNGo

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

4 weeks ago
UNKNOWNGo

Authorization bypass in serve restic in github.com/rclone/rclone

Authorization bypass in serve restic in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

4 weeks ago
UNKNOWNGo

Unsafe file permission restoration from metadata in github.com/rclone/rclone

Unsafe file permission restoration from metadata in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Arbitrary file write via --links symlinks in github.com/rclone/rclone

Arbitrary file write via --links symlinks in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

FTP command injection via custom encoding in github.com/rclone/rclone

FTP command injection via custom encoding in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Path traversal via crafted archive paths in github.com/rclone/rclone

Path traversal via crafted archive paths in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

4 weeks ago
UNKNOWNGo

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Path traversal via local backend encoding in github.com/rclone/rclone

Path traversal via local backend encoding in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Command execution via PowerShell smart quotes in github.com/rclone/rclone

Command execution via PowerShell smart quotes in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Path traversal in serve restic in github.com/rclone/rclone

Path traversal in serve restic in github.com/rclone/rclone

4 weeks ago
UNKNOWNGo

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

4 weeks ago
UNKNOWNGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

4 weeks ago
UNKNOWNGo

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

4 weeks ago
UNKNOWNGo

Stale blob descriptor cache invalidation in github.com/distribution/distribution

Stale blob descriptor cache invalidation in github.com/distribution/distribution

4 weeks ago
UNKNOWNGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

4 weeks ago
UNKNOWNGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

4 weeks ago
UNKNOWNGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

4 weeks ago
UNKNOWNGo

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

4 weeks ago
MODERATEGo

uniget CLI has an EDITOR Command Injection

uniget CLI has an EDITOR Command Injection

4 weeks ago
MODERATEGo

package pkcs12: Authentication bypass in Decode functions

package pkcs12: Authentication bypass in Decode functions

4 weeks ago
MODERATEGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

4 weeks ago
HIGHGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

4 weeks ago
HIGHGo

New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API: Integer overflow in quota billing yields negative charges (self-crediting)

4 weeks ago
MODERATEGo

New API: Admin can reset passkeys for same-level or higher-privileged users

New API: Admin can reset passkeys for same-level or higher-privileged users

github.com/QuantumNous/new-api: 0.9.1.3 → 1.0.0-rc.7

4 weeks ago
MODERATEGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

4 weeks ago
MODERATEGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

4 weeks ago
CRITICALGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

4 weeks ago
CRITICALGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

4 weeks ago
MODERATEGo

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

4 weeks ago
CRITICALGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

4 weeks ago
HIGHGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

4 weeks ago
UNKNOWNGo

Excessive memory allocation during VP8L decoding in golang.org/x/image

Excessive memory allocation during VP8L decoding in golang.org/x/image

4 weeks ago
UNKNOWNGo

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

4 weeks ago
HIGHGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

4 weeks ago
UNKNOWNGo

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

4 weeks ago
UNKNOWNGo

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

4 weeks ago
UNKNOWNGo

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

4 weeks ago
UNKNOWNGo

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

4 weeks ago
UNKNOWNGo

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

4 weeks ago
UNKNOWNGo

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

4 weeks ago
UNKNOWNGo

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

4 weeks ago
HIGHGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

4 weeks ago
HIGHGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

4 weeks ago
UNKNOWNGo

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

1 month ago
UNKNOWNGo

Unauthenticated backend instantiation in github.com/rclone/rclone

Unauthenticated backend instantiation in github.com/rclone/rclone

1 month ago
UNKNOWNGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

1 month ago
UNKNOWNGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

1 month ago
UNKNOWNGo

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

1 month ago
UNKNOWNGo

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

1 month ago
UNKNOWNGo

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

1 month ago
UNKNOWNGo

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

1 month ago
UNKNOWNGo

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

1 month ago
UNKNOWNGo

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

1 month ago
HIGHGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

1 month ago
HIGHGo

go-git: Worktree operations may follow symlinks

go-git: Worktree operations may follow symlinks

1 month ago
HIGHGo

go-git: Malicious reference names may modify files outside the reference storage

go-git: Malicious reference names may modify files outside the reference storage

1 month ago
MODERATEGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

1 month ago
HIGHGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

1 month ago
HIGHGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

1 month ago
HIGHGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

1 month ago
HIGHGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

1 month ago
MEDIUMGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

1 month ago
HIGHGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

1 month ago
LOWGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

1 month ago
MODERATEGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

1 month ago
HIGHGo

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

1 month ago
HIGHGo

rclone: Incomplete path validation allows backend root escape in serve restic

rclone: Incomplete path validation allows backend root escape in serve restic

1 month ago
HIGHGo

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

1 month ago
HIGHGo

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

1 month ago
HIGHGo

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

1 month ago
HIGHGo

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

1 month ago
CRITICALGo

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

1 month ago
MEDIUMGo

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

1 month ago
CRITICALGo

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

1 month ago
MODERATEGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

1 month ago
MEDIUMGo

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

1 month ago
MEDIUMGo

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

1 month ago
MEDIUMGo

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

1 month ago
MEDIUMGo

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

1 month ago
MODERATEGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

1 month ago
HIGHGo

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

1 month ago
HIGHGo

rclone: Local Encoding Path Traversal

rclone: Local Encoding Path Traversal

1 month ago
MEDIUMGo

sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go fails to check signature timestamps against a signing key's validity period

1 month agoEPSS 0%
MODERATEGo

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

1 month agoEPSS 0%
MEDIUMGo

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

1 month agoEPSS 0%
HIGHGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

1 month agoEPSS 0%
HIGHGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

1 month agoEPSS 0%
HIGHGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

1 month agoEPSS 0%
HIGHGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

1 month agoEPSS 0%
HIGHGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

1 month agoEPSS 0%
MEDIUMGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

1 month agoEPSS 0%
MODERATEGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

1 month agoEPSS 0%
CRITICALGo

Wings exposes node configuration secrets through egg configuration-file templating

Wings exposes node configuration secrets through egg configuration-file templating

1 month agoEPSS 0%
CRITICALGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

1 month agoEPSS 1%
MEDIUMGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

1 month agoEPSS 0%
HIGHGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

1 month agoEPSS 0%
HIGHGo

netfoil: Incorrect block responses could lead to localhost traffic

netfoil: Incorrect block responses could lead to localhost traffic

1 month ago
CRITICALGo

Logging operator has Fluentd configuration injection that allows remote code execution

Logging operator has Fluentd configuration injection that allows remote code execution

1 month agoEPSS 0%
HIGHGo

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

1 month agoEPSS 0%
CRITICALGo

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

1 month agoEPSS 0%
MODERATEGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

1 month agoEPSS 0%
MODERATEGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

1 month agoEPSS 0%
MEDIUMGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

1 month ago
MEDIUMGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

1 month ago
HIGHGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

1 month ago
HIGHGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

1 month ago
HIGHGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

1 month ago
HIGHGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

1 month ago
HIGHGo

openhole-server vulnerable to path traversal via URL-decoded request path

openhole-server vulnerable to path traversal via URL-decoded request path

1 month ago
HIGHGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

1 month ago
HIGHGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

1 month ago
HIGHGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

1 month ago
MEDIUMGo

goshs has a Path Traversal issue

goshs has a Path Traversal issue

1 month ago
MEDIUMGo

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

1 month ago
HIGHGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

1 month ago
MEDIUMGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

1 month ago
MODERATEGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

1 month ago
HIGHGo

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

1 month ago
UNKNOWNGo

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

1 month agoEPSS 0%
UNKNOWNGo

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 month ago
UNKNOWNGo

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 month ago
UNKNOWNGo

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 month ago
UNKNOWNGo

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

1 month ago
UNKNOWNGo

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

1 month ago
HIGHGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

1 month ago
HIGHGo

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

1 month ago
UNKNOWNGo

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

1 month ago
UNKNOWNGo

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

1 month ago
UNKNOWNGo

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

1 month ago
CRITICALGo

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

1 month ago
UNKNOWNGo

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

1 month ago
MEDIUMGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

1 month ago
HIGHGo

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

1 month ago
UNKNOWNGo

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

1 month ago
MODERATEGo

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

1 month ago
UNKNOWNGo

Hardlink path traversal during tar extraction in oras.land/oras-go

Hardlink path traversal during tar extraction in oras.land/oras-go

1 month agoEPSS 0%
HIGHGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

1 month ago
MEDIUMGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

1 month ago
MEDIUMGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

1 month ago
HIGHGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

1 month ago
HIGHGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

1 month ago
HIGHGo

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

1 month ago
HIGHGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

1 month ago
UNKNOWNGo

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

1 month ago
UNKNOWNGo

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

1 month ago
MEDIUMGo

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

1 month ago
HIGHGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

1 month ago
MEDIUMGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

1 month ago
MEDIUMGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

1 month ago
MEDIUMGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

1 month ago
UNKNOWNGo

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

1 month ago
UNKNOWNGo

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

1 month ago
HIGHGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

1 month ago
UNKNOWNGo

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

1 month agoEPSS 0%
MEDIUMGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

1 month ago
UNKNOWNGo

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

1 month ago
UNKNOWNGo

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

1 month ago
UNKNOWNGo

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

1 month ago
UNKNOWNGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

1 month ago
UNKNOWNGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

1 month ago
UNKNOWNGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

1 month ago
UNKNOWNGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

1 month ago
HIGHGo

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

1 month ago
HIGHGo

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

1 month ago
MODERATEGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

1 month ago
LOWGo

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

2 months ago
UNKNOWNGo

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

2 months ago
MODERATEGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

2 months ago
HIGHGo

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

2 months ago
HIGHGo

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

2 months ago
HIGHGo

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header

2 months ago
HIGHGo

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock

2 months ago
MODERATEGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured

kumactl connects to control plane without verifying TLS certificate when no CA is configured

2 months ago
HIGHGo

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit

2 months ago
HIGHGo

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization

2 months ago
HIGHGo

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass

2 months ago
HIGHGo

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

2 months agoEPSS 0%
HIGHGo

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

2 months ago
HIGHGo

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

2 months ago
HIGHGo

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

2 months ago
UNKNOWNGo

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

2 months ago
UNKNOWNGo

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

2 months ago
CRITICALGo

melange: Incomplete package integrity verification allows data section substitution

melange: Incomplete package integrity verification allows data section substitution

2 months ago
HIGHGo

sigstore-go has a multi-log threshold bypass via single compromised log

sigstore-go has a multi-log threshold bypass via single compromised log

2 months agoEPSS 0%
HIGHGo

GoBGP confederation validation panics on empty AS_PATH attribute

GoBGP confederation validation panics on empty AS_PATH attribute

2 months ago
UNKNOWNGo

Concourse login flow has an open redirect issue in github.com/concourse/concourse

Concourse login flow has an open redirect issue in github.com/concourse/concourse

2 months ago
UNKNOWNGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

2 months ago
UNKNOWNGo

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream

2 months ago
HIGHGo

KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

2 months ago
UNKNOWNGo

Root escape via symlink plus trailing slash in os

Root escape via symlink plus trailing slash in os

2 months ago
UNKNOWNGo

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour

2 months ago
UNKNOWNGo

Invoking Encrypted Client Hello privacy leak in crypto/tls

Invoking Encrypted Client Hello privacy leak in crypto/tls

2 months agoEPSS 0%
HIGHGo

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

2 months ago
CRITICALGo

Gitea LFS mirror operations bypass migration HTTP transport protections

Gitea LFS mirror operations bypass migration HTTP transport protections

2 months ago
HIGHGo

Gitea OAuth2 PKCE S256 verifier bypass

Gitea OAuth2 PKCE S256 verifier bypass

2 months ago
HIGHGo

Gitea template repository generation follows unsafe filesystem paths

Gitea template repository generation follows unsafe filesystem paths

2 months ago
HIGHGo

Gitea git grep searches allow server resource exhaustion

Gitea git grep searches allow server resource exhaustion

2 months ago
HIGHGo

Gitea organization permission APIs expose hidden membership and private organization data

Gitea organization permission APIs expose hidden membership and private organization data

2 months ago
HIGHGo

Gitea primary email ownership bypass allows cross-user email changes

Gitea primary email ownership bypass allows cross-user email changes

2 months ago
HIGHGo

Gitea repository creation accepts insufficiently validated fields

Gitea repository creation accepts insufficiently validated fields

2 months ago
MEDIUMGo

Gitea release asset dumps permit path traversal through crafted names

Gitea release asset dumps permit path traversal through crafted names

2 months ago
HIGHGo

Gitea OAuth2 authorization codes can be reused after expiry

Gitea OAuth2 authorization codes can be reused after expiry

2 months ago
HIGHGo

Gitea pull request branch permission checks allow unauthorized updates and rebases

Gitea pull request branch permission checks allow unauthorized updates and rebases

2 months ago
MEDIUMGo

Gitea exposes tracked time entries without repository authorization

Gitea exposes tracked time entries without repository authorization

2 months ago
MEDIUMGo

Gitea tracked-time deletion is not scoped to the requested issue

Gitea tracked-time deletion is not scoped to the requested issue

2 months ago
HIGHGo

Gitea draft releases and attachments are exposed without write permission

Gitea draft releases and attachments are exposed without write permission

2 months ago
CRITICALGo

Gitea pre-receive hook scanner errors allow branch-protection bypass

Gitea pre-receive hook scanner errors allow branch-protection bypass

2 months ago
HIGHGo

Gitea forwarded-proto validation allows canonical URL spoofing

Gitea forwarded-proto validation allows canonical URL spoofing

2 months ago
HIGHGo

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

2 months ago
HIGHGo

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

2 months ago
MEDIUMGo

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

2 months agoEPSS 0%
HIGHGo

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

2 months ago
LOWGo

Concourse login flow has an open redirect issue

Concourse login flow has an open redirect issue

2 months ago
CRITICALGo

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

2 months ago
MODERATEGo

oras-go has file store write outside workingDir via symlink traversal

oras-go has file store write outside workingDir via symlink traversal

2 months ago
CRITICALGo

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

2 months ago
MODERATEGo

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

2 months ago
HIGHGo

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

2 months agoEPSS 0%
LOWGo

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

2 months ago
MEDIUMGo

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

2 months ago
CRITICALGo

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

2 months ago
HIGHGo

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality

2 months ago
HIGHGo

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

2 months ago
HIGHGo

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints

2 months ago
CRITICALGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

2 months ago
HIGHGo

regclient may leak authentication credentials to external blob stores

regclient may leak authentication credentials to external blob stores

2 months ago
MODERATEGo

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

2 months ago
UNKNOWNGo

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

2 months ago
UNKNOWNGo

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

2 months agoEPSS 1%
UNKNOWNGo

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0

2 months ago
MEDIUMGo

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

2 months agoEPSS 1%
HIGHGo

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto vulnerable to infinite loop on large channel writes

2 months ago
UNKNOWNGo

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

2 months ago
UNKNOWNGo

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

2 months ago
MEDIUMGo

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

2 months ago
UNKNOWNGo

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0

2 months ago
UNKNOWNGo

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0

2 months ago
UNKNOWNGo

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0

2 months ago
HIGHGo

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

2 months ago
HIGHGo

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

2 months ago
UNKNOWNGo

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0

2 months ago
HIGHGo

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

2 months ago
UNKNOWNGo

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0

2 months ago
MEDIUMGo

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

2 months ago
HIGHGo

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

2 months ago
HIGHGo

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

2 months ago
UNKNOWNGo

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

2 months ago
UNKNOWNGo

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

2 months ago
UNKNOWNGo

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

2 months ago
UNKNOWNGo

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0

2 months ago
UNKNOWNGo

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

2 months ago
HIGHGo

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto doesn't enforce invoking key constraints

2 months ago
UNKNOWNGo

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

2 months ago
UNKNOWNGo

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno

2 months ago
UNKNOWNGo

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

2 months ago
UNKNOWNGo

Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0

Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0

2 months ago
HIGHGo

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

2 months agoEPSS 1%
UNKNOWNGo

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0

2 months ago
UNKNOWNGo

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation

2 months ago
UNKNOWNGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

2 months ago
HIGHGo

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent

2 months ago
HIGHGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

2 months ago
MEDIUMGo

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

2 months ago
HIGHGo

Gophish contains a denial of service vulnerability

Gophish contains a denial of service vulnerability

2 months ago
HIGHGo

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

2 months ago
HIGHGo

containerd CRI checkpoint restore CDI annotation smuggling

containerd CRI checkpoint restore CDI annotation smuggling

2 months ago
HIGHGo

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

2 months ago
HIGHGo

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

2 months ago
MODERATEGo

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

2 months ago
CRITICALGo

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

2 months ago
MEDIUMGo

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

2 months ago
CRITICALGo

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

2 months ago
HIGHGo

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

2 months ago
HIGHGo

Grafana Tempo vulnerable to an out-of-memory crash

Grafana Tempo vulnerable to an out-of-memory crash

2 months ago
MEDIUMGo

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

2 months ago
HIGHGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

2 months ago
HIGHGo

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

3 months ago
CRITICALGo

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

3 months ago
HIGHGo

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

3 months ago
HIGHGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

3 months ago
HIGHGo

Filestash allows attackers to escalate privileges via sending a crafted request

Filestash allows attackers to escalate privileges via sending a crafted request

3 months ago
HIGHGo

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request

linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request

3 months ago
CRITICALGo

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

statping-ng allows attackers to escalate privileges to Administrator and access sensitive components

3 months ago
CRITICALGo

MCP Toolbox for Databases has an Origin Validation Error

MCP Toolbox for Databases has an Origin Validation Error

3 months ago
HIGHGo

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

3 months ago
HIGHGo

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

3 months ago
CRITICALGo

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

3 months ago
HIGHGo

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

3 months ago
MEDIUMGo

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

3 months ago
HIGHGo

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

3 months ago
HIGHGo

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

3 months ago
MEDIUMGo

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

3 months ago
MEDIUMGo

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

3 months ago
HIGHGo

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

3 months ago
HIGHGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

3 months ago
HIGHGo

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

3 months ago
CRITICALGo

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

3 months ago
CRITICALGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

3 months ago
HIGHGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

3 months ago
HIGHGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

3 months ago
HIGHGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

3 months ago
HIGHGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

3 months ago
HIGHGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

3 months agoEPSS 0%
HIGHGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

3 months agoEPSS 0%
MEDIUMGo

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

3 months agoEPSS 0%
MEDIUMGo

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

3 months agoEPSS 0%
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

3 months ago
MEDIUMGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

3 months ago
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

3 months ago
MEDIUMGo

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

3 months ago
MEDIUMGo

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

3 months ago
UNKNOWNGo

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

3 months agoEPSS 1%
UNKNOWNGo

Arbitrary inputs are included in errors without any escaping in net/textproto

Arbitrary inputs are included in errors without any escaping in net/textproto

3 months agoEPSS 0%
UNKNOWNGo

Inefficient candidate hostname parsing in crypto/x509

Inefficient candidate hostname parsing in crypto/x509

3 months agoEPSS 1%
HIGHGo

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

3 months ago
MEDIUMGo

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

3 months ago
HIGHGo

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

3 months ago
HIGHGo

go-git: Malformed Git object data may cause panics or resource exhaustion

go-git: Malformed Git object data may cause panics or resource exhaustion

3 months ago
HIGHGo

KubeVirt has a Link Following issue

KubeVirt has a Link Following issue

3 months ago
MEDIUMGo

opentelemetry-go's baggage parsing no longer caps raw header length

opentelemetry-go's baggage parsing no longer caps raw header length

3 months ago
HIGHGo

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

3 months ago
HIGHGo

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

3 months ago
HIGHGo

Go Net HTML parser is vulnerable to denial of service

Go Net HTML parser is vulnerable to denial of service

3 months ago
CRITICALGo

KubeVirt has a Link Following vulnerability

KubeVirt has a Link Following vulnerability

3 months ago
UNKNOWNGo

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

3 months ago
UNKNOWNGo

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

3 months ago
UNKNOWNGo

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

3 months ago
UNKNOWNGo

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

3 months ago
UNKNOWNGo

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

3 months ago
UNKNOWNGo

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

3 months ago
UNKNOWNGo

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

3 months ago
CRITICALGo

containerd user ID handling bypass allows runAsNonRoot evasion

containerd user ID handling bypass allows runAsNonRoot evasion

3 months ago
UNKNOWNGo

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

3 months ago
MEDIUMGo

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server

3 months ago
MEDIUMGo

MCP Registry: OCI validator skips ownership check on upstream rate limits

MCP Registry: OCI validator skips ownership check on upstream rate limits

3 months ago
HIGHGo

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

3 months ago
HIGHGo

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

3 months ago
HIGHGo

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

3 months ago
LOWGo

go-git: Improper single-quote escaping in go-git SSH transport

go-git: Improper single-quote escaping in go-git SSH transport

3 months ago
HIGHGo

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

3 months ago
HIGHGo

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

3 months ago
MEDIUMGo

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

3 months ago
HIGHGo

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

3 months ago
HIGHGo

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

3 months ago
MEDIUMGo

go-git: Crafted repositories may modify main and submodule .git directories

go-git: Crafted repositories may modify main and submodule .git directories

3 months ago
HIGHGo

iskorotkov/avro: CPU Exhaustion in Decoder

iskorotkov/avro: CPU Exhaustion in Decoder

4 months ago
HIGHGo

iskorotkov/avro: Integer Overflow in Decoder

iskorotkov/avro: Integer Overflow in Decoder

4 months ago
HIGHGo

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

4 months ago
HIGHGo

Docker: `PUT /containers/{id}/archive` executes container binary on the host

Docker: `PUT /containers/{id}/archive` executes container binary on the host

4 months ago
HIGHGo

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

4 months ago
HIGHGo

Docker: Race condition in docker cp allows bind mount redirection to host path

Docker: Race condition in docker cp allows bind mount redirection to host path

4 months ago
MODERATEGo

slack-go `SecretsVerifier` accepts empty signing secret without precondition

slack-go `SecretsVerifier` accepts empty signing secret without precondition

4 months ago
HIGHGo

go-billy has path traversal vulnerabilities

go-billy has path traversal vulnerabilities

4 months ago
MODERATEGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

4 months ago
HIGHGo

Grafana: SQL Expressions Read File From Disk

Grafana: SQL Expressions Read File From Disk

4 months ago
HIGHGo

Grafana: Users can generate Service Account tokens after permissions removal

Grafana: Users can generate Service Account tokens after permissions removal

4 months ago
HIGHGo

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

4 months ago
HIGHGo

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

4 months ago
CRITICALGo

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

4 months ago
HIGHGo

gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits

gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits

4 months ago
MEDIUMGo

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience

MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience

4 months ago
MEDIUMGo

MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`

MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`

4 months ago
MEDIUMGo

MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist

MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist

4 months ago
HIGHGo

in-toto-golang and in-toto-python have inconsistent negation behavior

in-toto-golang and in-toto-python have inconsistent negation behavior

4 months ago
MEDIUMGo

gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers

gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers

4 months ago
MODERATEGo

MCP Registry has open redirect via protocol-relative path in trailing-slash middleware

MCP Registry has open redirect via protocol-relative path in trailing-slash middleware

4 months ago
MEDIUMGo

ExternalSecrets vulnerable to privilege escalation with secret overwriting

ExternalSecrets vulnerable to privilege escalation with secret overwriting

4 months ago
MEDIUMGo

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation

4 months ago
UNKNOWNGo

Quadratic string concatentation in consumeComment in net/mail

Quadratic string concatentation in consumeComment in net/mail

4 months ago
HIGHGo

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft

4 months ago
MEDIUMGo

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

4 months ago
UNKNOWNGo

Crash when handling long CNAME response in net

Crash when handling long CNAME response in net

4 months agoEPSS 1%
CRITICALGo

Rancher Extensions have arbitrary file access via path traversal

Rancher Extensions have arbitrary file access via path traversal

4 months ago
HIGHGo

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

4 months ago
LOWGo

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

4 months ago
UNKNOWNGo

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

4 months ago
UNKNOWNGo

Quadratic string concatenation in consumePhrase in net/mail

Quadratic string concatenation in consumePhrase in net/mail

4 months ago
MEDIUMGo

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers

4 months ago
HIGHGo

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI

4 months ago
MEDIUMGo

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count

4 months ago
MEDIUMGo

Ech0 comment model's Email field returned on public /api/comments endpoints

Ech0 comment model's Email field returned on public /api/comments endpoints

4 months ago
UNKNOWNGo

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

4 months ago
UNKNOWNGo

Escaper bypass leads to XSS in html/template

Escaper bypass leads to XSS in html/template

4 months ago
UNKNOWNGo

Bypass of meta content URL escaping causes XSS in html/template

Bypass of meta content URL escaping causes XSS in html/template

4 months ago
UNKNOWNGo

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Panic in Dial and LookupPort when handling NUL byte on Windows in net

4 months agoEPSS 1%
HIGHGo

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

4 months ago
UNKNOWNGo

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

4 months ago
HIGHGo

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo

Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo

4 months ago
UNKNOWNGo

Invoking "go tool pack" does not sanitize output paths in cmd/go

Invoking "go tool pack" does not sanitize output paths in cmd/go

4 months ago
UNKNOWNGo

Malicious module proxy can bypass checksum database in cmd/go

Malicious module proxy can bypass checksum database in cmd/go

4 months ago
HIGHGo

opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay

opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay

4 months ago
HIGHGo

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

4 months ago
MEDIUMGo

Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component

Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component

4 months ago
HIGHGo

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

4 months ago
MEDIUMGo

Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

4 months ago
HIGHGo

Prometheus Azure AD remote write OAuth client secret exposed via config API

Prometheus Azure AD remote write OAuth client secret exposed via config API

4 months ago
HIGHGo

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

4 months ago
MODERATEGo

Fiber vulnerable to XSS in AutoFormat Content Negotiation

Fiber vulnerable to XSS in AutoFormat Content Negotiation

4 months ago
MODERATEGo

External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore

External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore

4 months ago
LOWGo

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

4 months ago
HIGHGo

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery

4 months ago
HIGHGo

apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root

apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root

4 months ago
HIGHGo

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

4 months ago
MODERATEGo

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

4 months ago
HIGHGo

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)

4 months ago
HIGHGo

Argo has Missing Authorization in its Sync ConfigMap Provider

Argo has Missing Authorization in its Sync ConfigMap Provider

4 months ago
MODERATEGo

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

4 months ago
HIGHGo

Argo vulnerable to exposure of artifact repository credentials

Argo vulnerable to exposure of artifact repository credentials

4 months ago
HIGHGo

CoreDNS' DoQ worker pool does not bound stream backlog

CoreDNS' DoQ worker pool does not bound stream backlog

4 months ago
HIGHGo

CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC

CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC

4 months ago
HIGHGo

CoreDNS has TSIG authentication bypass on gRPC and QUIC transports

CoreDNS has TSIG authentication bypass on gRPC and QUIC transports

4 months ago
HIGHGo

Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability

Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability

4 months ago
HIGHGo

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

4 months ago
HIGHGo

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

4 months ago
MEDIUMGo

Ollama is Vulnerable to Path Traversal

Ollama is Vulnerable to Path Traversal

4 months ago
HIGHGo

Cillium exposes sensitive information included in the cilium-bugtool debug archive

Cillium exposes sensitive information included in the cilium-bugtool debug archive

4 months ago
HIGHGo

Contour has Lua code injection via Cookie Path Rewrite Policy

Contour has Lua code injection via Cookie Path Rewrite Policy

4 months ago
HIGHGo

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

4 months ago
CRITICALGo

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

4 months ago
HIGHGo

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

4 months ago
HIGHGo

Grafana Tempo has an Uncontrolled Resource Consumption issue

Grafana Tempo has an Uncontrolled Resource Consumption issue

4 months ago
HIGHGo

Kyverno Controller Denial of Service via forEach Mutation Panic

Kyverno Controller Denial of Service via forEach Mutation Panic

4 months ago
HIGHGo

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller

4 months ago
MEDIUMGo

go-ntlmssp NTLM challenges can panic on malformed payloads

go-ntlmssp NTLM challenges can panic on malformed payloads

4 months ago
LOWGo

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

4 months ago
CRITICALGo

Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution

Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution

4 months ago
MEDIUMGo

OpenFGA has Improper Policy Enforcement

OpenFGA has Improper Policy Enforcement

4 months ago
CRITICALGo

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

4 months ago
HIGHGo

Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion

Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion

4 months ago
HIGHGo

OpenBao's SQL Injection in PostgreSQL database secrets engine

OpenBao's SQL Injection in PostgreSQL database secrets engine

4 months ago
MEDIUMGo

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

4 months ago
CRITICALGo

Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE

Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE

4 months ago
MEDIUMGo

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

4 months ago
LOWGo

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

4 months ago
HIGHGo

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching

Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching

4 months ago
MEDIUMGo

Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check

Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check

4 months ago
HIGHGo

Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL

Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL

4 months ago
MEDIUMGo

go-git: Credential leak via cross-host redirect in smart HTTP transport

go-git: Credential leak via cross-host redirect in smart HTTP transport

5 months ago
MEDIUMGo

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

5 months ago
HIGHGo

HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service

HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service

5 months ago
HIGHGo

Dapr: Service Invocation path traversal ACL bypass

Dapr: Service Invocation path traversal ACL bypass

5 months ago
MEDIUMGo

goldmark vulnerable to Cross-site Scripting (XSS)

goldmark vulnerable to Cross-site Scripting (XSS)

5 months ago
HIGHGo

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

5 months ago
CRITICALGo

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization

5 months ago
HIGHGo

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)

5 months ago
HIGHGo

Kyverno: ServiceAccount token leaked to external servers via apiCall service URL

Kyverno: ServiceAccount token leaked to external servers via apiCall service URL

5 months ago
HIGHGo

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

5 months ago
HIGHGo

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

5 months ago
HIGHGo

SpdyStream: DOS on CRI

SpdyStream: DOS on CRI

5 months ago
MEDIUMGo

Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots

Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots

5 months ago
CRITICALGo

ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

5 months ago
MEDIUMGo

Istio: SSRF via RequestAuthentication jwksUri

Istio: SSRF via RequestAuthentication jwksUri

5 months ago
HIGHGo

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

5 months ago
MEDIUMGo

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

5 months ago
HIGHGo

Pyroscope Exposes Storage Secret

Pyroscope Exposes Storage Secret

5 months ago
MEDIUMGo

KubeVirt's authorization mechanism improperly truncates subresource names

KubeVirt's authorization mechanism improperly truncates subresource names

5 months ago
HIGHGo

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

5 months ago
CRITICALGo

PowerShell Command Injection in Podman HyperV Machine

PowerShell Command Injection in Podman HyperV Machine

5 months ago
HIGHGo

MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads

MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads

5 months ago
HIGHGo

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF

Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF

5 months ago
HIGHGo

Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access

Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access

5 months ago
HIGHGo

kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token

kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token

5 months ago
HIGHGo

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

5 months ago
HIGHGo

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach

Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach

5 months ago
HIGHGo

MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads

MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads

5 months ago
HIGHGo

External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine

External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine

5 months ago
MEDIUMGo

Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer

Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer

5 months ago
HIGHGo

SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

github.com/siyuan-note/siyuan/kernel: before 3.6.40.0.0-20260407035653-2f416e5253f1

5 months ago
MEDIUMGo

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation

Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation

5 months ago
MODERATEGo

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

5 months ago
MODERATEGo

Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint

Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint

5 months ago
CRITICALGo

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

5 months ago
HIGHGo

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export

5 months ago
CRITICALGo

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

5 months ago
MEDIUMGo

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure

Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure

5 months ago
HIGHGo

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session

Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session

5 months ago
HIGHGo

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs

Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs

5 months ago
MEDIUMGo

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload

Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload

5 months ago
CRITICALGo

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

5 months ago
CRITICALGo

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

5 months ago
CRITICALGo

LXD: Importing a crafted backup leads to project restriction bypass

LXD: Importing a crafted backup leads to project restriction bypass

5 months ago
HIGHGo

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass

Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass

5 months ago
HIGHGo

MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing

5 months ago
HIGHGo

HashiCorp's go-getter library may allow arbitrary file reads

HashiCorp's go-getter library may allow arbitrary file reads

5 months ago
HIGHGo

kcp's cache server is accessible without authentication or authorization checks

kcp's cache server is accessible without authentication or authorization checks

5 months ago
MEDIUMGo

OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response

OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response

5 months ago
HIGHGo

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies

5 months ago
HIGHGo

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

5 months ago
HIGHGo

mercure has Topic Selector Cache Key Collision

mercure has Topic Selector Cache Key Collision

5 months ago
HIGHGo

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

5 months ago
MEDIUMGo

Cosign's verify-blob-attestation reports false positive when payload parsing fails

Cosign's verify-blob-attestation reports false positive when payload parsing fails

5 months ago
CRITICALGo

File Browser has a Command Injection via Hook Runner

File Browser has a Command Injection via Hook Runner

5 months ago
CRITICALGo

pgx contains memory-safety vulnerability

pgx contains memory-safety vulnerability

5 months ago
HIGHGo

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

5 months ago
UNKNOWNGo

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

5 months agoEPSS 1%
UNKNOWNGo

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

5 months agoEPSS 1%
UNKNOWNGo

Unexpected work during chain building in crypto/x509

Unexpected work during chain building in crypto/x509

5 months agoEPSS 1%
MEDIUMGo

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

5 months ago
UNKNOWNGo

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

5 months ago
UNKNOWNGo

Inefficient policy validation in crypto/x509

Inefficient policy validation in crypto/x509

5 months agoEPSS 0%
UNKNOWNGo

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

5 months agoEPSS 0%
CRITICALGo

Memory-safety vulnerability in github.com/jackc/pgx/v5.

Memory-safety vulnerability in github.com/jackc/pgx/v5.

5 months ago
UNKNOWNGo

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

5 months agoEPSS 0%
HIGHGo

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers

5 months ago
HIGHGo

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

5 months ago
HIGHGo

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm

5 months ago
HIGHGo

Go JOSE Panics in JWE decryption

Go JOSE Panics in JWE decryption

5 months ago
CRITICALGo

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

5 months ago
LOWGo

Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster

Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster

5 months ago
HIGHGo

go-git: Maliciously crafted idx file can cause asymmetric memory consumption

go-git: Maliciously crafted idx file can cause asymmetric memory consumption

5 months ago
CRITICALGo

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

github.com/0xJacky/Nginx-UI: all versions

5 months ago
HIGHGo

nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse

nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse

github.com/0xJacky/Nginx-UI: all versions

5 months ago
MODERATEGo

Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation

Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation

github.com/0xJacky/Nginx-UI: all versions

5 months ago
CRITICALGo

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

github.com/0xJacky/nginx-ui: all versions

5 months ago
MEDIUMGo

go-git missing validation decoding Index v4 files leads to panic

go-git missing validation decoding Index v4 files leads to panic

5 months ago
MODERATEGo

nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval

nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval

github.com/0xJacky/Nginx-UI: all versions

5 months ago
HIGHGo

XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

5 months ago
HIGHGo

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

5 months ago
CRITICALGo

Flannel has cross-node remote code execution via extension backend BackendData injection

Flannel has cross-node remote code execution via extension backend BackendData injection

5 months ago
CRITICALGo

Moby has AuthZ plugin bypass when provided oversized request bodies

Moby has AuthZ plugin bypass when provided oversized request bodies

5 months ago
MODERATEGo

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

5 months ago
HIGHGo

Grafana Tempo has Inadequate Encryption Strength

Grafana Tempo has Inadequate Encryption Strength

5 months ago
MODERATEGo

Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField

Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField

5 months ago
HIGHGo

Moby has an Off-by-one error in its plugin privilege validation

Moby has an Off-by-one error in its plugin privilege validation

5 months ago
HIGHGo

Grafana public dashboards disclose all direct mode datasources

Grafana public dashboards disclose all direct mode datasources

5 months ago
HIGHGo

MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

5 months ago
MODERATEGo

OpenFGA has an Authorization Bypass through cached keys

OpenFGA has an Authorization Bypass through cached keys

5 months ago
HIGHGo

BuildKit Git URL subdir component can cause access to restricted files

BuildKit Git URL subdir component can cause access to restricted files

5 months ago
MEDIUMGo

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

5 months ago
CRITICALGo

BuildKit's Malicious frontend can cause file escape outside of storage root

BuildKit's Malicious frontend can cause file escape outside of storage root

5 months ago
MEDIUMGo

Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic

Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic

5 months ago
HIGHGo

NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead

NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead

5 months ago
MEDIUMGo

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

5 months ago
MEDIUMGo

NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing

NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing

5 months ago
MEDIUMGo

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

5 months ago
MEDIUMGo

NATS: Message tracing can be redirected to arbitrary subject

NATS: Message tracing can be redirected to arbitrary subject

5 months ago
MEDIUMGo

NATS is vulnerable to pre-auth DoS through WebSockets client service

NATS is vulnerable to pre-auth DoS through WebSockets client service

5 months ago
CRITICALGo

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

aquasecurity/trivy-action: before 0.35.0

5 months ago
HIGHGo

NATS Server panic via malicious compression on leafnode port

NATS Server panic via malicious compression on leafnode port

5 months ago
MEDIUMGo

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

5 months ago
HIGHGo

NATS JetStream has an authorization bypass through its Management API

NATS JetStream has an authorization bypass through its Management API

5 months ago
HIGHGo

NATS allows MQTT clients to bypass ACL checks

NATS allows MQTT clients to bypass ACL checks

5 months ago
HIGHGo

NATS has pre-auth server panic via leafnode handling

NATS has pre-auth server panic via leafnode handling

5 months ago
HIGHGo

NATS credentials are exposed in monitoring port via command-line argv

NATS credentials are exposed in monitoring port via command-line argv

5 months ago
HIGHGo

NATS is vulnerable to MQTT hijacking via Client ID

NATS is vulnerable to MQTT hijacking via Client ID

5 months ago
HIGHGo

NATS has MQTT plaintext password disclosure

NATS has MQTT plaintext password disclosure

5 months ago
MEDIUMGo

Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers

Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers

code.vikunja.io/api: 0.8 → 2.2.0

5 months ago
HIGHGo

Vikunja has TOTP Reuse During Validity Window

Vikunja has TOTP Reuse During Validity Window

code.vikunja.io/api: ≥ 0.13

5 months ago
CRITICALGo

MinIO LDAP login brute-force via user enumeration and missing rate limit

MinIO LDAP login brute-force via user enumeration and missing rate limit

5 months ago
HIGHGo

etcd: Authorization bypasses in multiple APIs

etcd: Authorization bypasses in multiple APIs

5 months ago
MEDIUMGo

Syft improper temporary file cleanup

Syft improper temporary file cleanup

5 months ago
CRITICALGo

Ory Hydra has a SQL injection via forged pagination tokens

Ory Hydra has a SQL injection via forged pagination tokens

5 months ago
LOWGo

etcd: Nested etcd transactions bypass RBAC authorization checks

etcd: Nested etcd transactions bypass RBAC authorization checks

5 months ago
HIGHGo

Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk

Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk

6 months ago
HIGHGo

Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk

Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk

6 months ago
HIGHGo

step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

6 months ago
CRITICALGo

MinIO has JWT Algorithm Confusion in OIDC Authentication

MinIO has JWT Algorithm Confusion in OIDC Authentication

6 months ago
HIGHGo

Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service

Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service

6 months ago
HIGHGo

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

6 months ago
HIGHGo

Packetbeat does not properly validate an array index in multiple protocol parser components

Packetbeat does not properly validate an array index in multiple protocol parser components

6 months ago
HIGHGo

gosaml2 CBC Padding Panic — Unauthenticated Process Crash

gosaml2 CBC Padding Panic — Unauthenticated Process Crash

6 months ago
MEDIUMGo

Zitadel is missing enforcement of organization scopes

Zitadel is missing enforcement of organization scopes

6 months ago
HIGHGo

gRPC-Go has an authorization bypass via missing leading slash in :path

gRPC-Go has an authorization bypass via missing leading slash in :path

6 months ago
HIGHGo

validateSignature Loop Variable Capture Signature Bypass in goxmldsig

validateSignature Loop Variable Capture Signature Bypass in goxmldsig

6 months ago
HIGHGo

File Browser has an Authorization Policy Bypass in Public Share Download Flow

File Browser has an Authorization Policy Bypass in Public Share Download Flow

6 months ago
HIGHGo

Denial of service in github.com/jackc/pgproto3/v2

Denial of service in github.com/jackc/pgproto3/v2

6 months ago
HIGHGo

github.com/buger/jsonparser has a denial of service vulnerability

github.com/buger/jsonparser has a denial of service vulnerability

6 months ago
HIGHGo

Denial of service in github.com/shamaton/msgpack

Denial of service in github.com/shamaton/msgpack

6 months ago
HIGHGo

Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod

Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod

6 months ago
HIGHGo

Unsigned SAML LogoutRequest Acceptance in gosaml2

Unsigned SAML LogoutRequest Acceptance in gosaml2

6 months ago
HIGHGo

Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun

Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun

6 months ago
MODERATEGo

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

6 months ago
HIGHGo

GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute

GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute

6 months ago
HIGHGo

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

6 months ago
HIGHGo

Unauthorized access to Argo Workflows Template

Unauthorized access to Argo Workflows Template

6 months ago
MODERATEGo

Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values

Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values

6 months ago
HIGHGo

CoreDNS Loop Detection Denial of Service Vulnerability

CoreDNS Loop Detection Denial of Service Vulnerability

6 months ago
UNKNOWNGo

Incorrect parsing of IPv6 host literals in net/url

Incorrect parsing of IPv6 host literals in net/url

6 months agoEPSS 1%

Tooling for Go

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionshexMavenNuGetPackagistPubPyPIRubyGemsSwiftURLcrates.ionpm