Go incidents

Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MEDIUMGo

sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go fails to check signature timestamps against a signing key's validity period

5 days agoEPSS 0%
HIGHGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

5 days agoEPSS 0%
HIGHGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

5 days agoEPSS 0%
MEDIUMGo

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

5 days agoEPSS 0%
MODERATEGo

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

5 days agoEPSS 0%
HIGHGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

5 days agoEPSS 0%
HIGHGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

5 days agoEPSS 0%
CRITICALGo

Wings exposes node configuration secrets through egg configuration-file templating

Wings exposes node configuration secrets through egg configuration-file templating

5 days agoEPSS 0%
HIGHGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

5 days agoEPSS 0%
MEDIUMGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

5 days agoEPSS 0%
MODERATEGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

5 days agoEPSS 0%
HIGHGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

6 days agoEPSS 0%
CRITICALGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

6 days agoEPSS 1%
MEDIUMGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

6 days agoEPSS 0%
CRITICALGo

Logging operator has Fluentd configuration injection that allows remote code execution

Logging operator has Fluentd configuration injection that allows remote code execution

1 week agoEPSS 0%
HIGHGo

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

1 week agoEPSS 0%
HIGHGo

netfoil: Incorrect block responses could lead to localhost traffic

netfoil: Incorrect block responses could lead to localhost traffic

1 week ago
CRITICALGo

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

1 week agoEPSS 0%
MODERATEGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

1 week agoEPSS 0%
MODERATEGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

1 week agoEPSS 0%
UNKNOWNGo

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 week ago
UNKNOWNGo

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 week ago
UNKNOWNGo

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

1 week ago
UNKNOWNGo

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

1 week agoEPSS 0%
UNKNOWNGo

Hardlink path traversal during tar extraction in oras.land/oras-go

Hardlink path traversal during tar extraction in oras.land/oras-go

1 week agoEPSS 0%
UNKNOWNGo

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

1 week agoEPSS 0%
HIGHGo

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

2 weeks ago
HIGHGo

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

3 weeks agoEPSS 0%
HIGHGo

sigstore-go has a multi-log threshold bypass via single compromised log

sigstore-go has a multi-log threshold bypass via single compromised log

3 weeks agoEPSS 0%
UNKNOWNGo

Invoking Encrypted Client Hello privacy leak in crypto/tls

Invoking Encrypted Client Hello privacy leak in crypto/tls

4 weeks agoEPSS 0%
MEDIUMGo

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

4 weeks agoEPSS 0%
HIGHGo

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

1 month agoEPSS 0%
HIGHGo

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

1 month agoEPSS 1%
HIGHGo

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

1 month agoEPSS 1%
MEDIUMGo

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

1 month agoEPSS 1%
HIGHGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

1 month agoEPSS 0%
MEDIUMGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

1 month agoEPSS 0%
MEDIUMGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

1 month agoEPSS 0%
MEDIUMGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

1 month agoEPSS 0%
MEDIUMGo

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

1 month agoEPSS 0%
HIGHGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

1 month agoEPSS 0%
MEDIUMGo

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

1 month agoEPSS 0%
UNKNOWNGo

Arbitrary inputs are included in errors without any escaping in net/textproto

Arbitrary inputs are included in errors without any escaping in net/textproto

2 months agoEPSS 0%
UNKNOWNGo

Inefficient candidate hostname parsing in crypto/x509

Inefficient candidate hostname parsing in crypto/x509

2 months agoEPSS 1%
UNKNOWNGo

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

2 months agoEPSS 1%
HIGHGo

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

2 months ago
HIGHGo

iskorotkov/avro: Integer Overflow in Decoder

iskorotkov/avro: Integer Overflow in Decoder

2 months ago
HIGHGo

iskorotkov/avro: CPU Exhaustion in Decoder

iskorotkov/avro: CPU Exhaustion in Decoder

2 months ago
UNKNOWNGo

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Panic in Dial and LookupPort when handling NUL byte on Windows in net

3 months agoEPSS 1%
UNKNOWNGo

Crash when handling long CNAME response in net

Crash when handling long CNAME response in net

3 months agoEPSS 1%
UNKNOWNGo

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

4 months agoEPSS 0%
UNKNOWNGo

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

4 months agoEPSS 1%
UNKNOWNGo

Inefficient policy validation in crypto/x509

Inefficient policy validation in crypto/x509

4 months agoEPSS 0%
UNKNOWNGo

Unexpected work during chain building in crypto/x509

Unexpected work during chain building in crypto/x509

4 months agoEPSS 1%
UNKNOWNGo

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

4 months agoEPSS 0%
UNKNOWNGo

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

4 months agoEPSS 1%
UNKNOWNGo

Incorrect parsing of IPv6 host literals in net/url

Incorrect parsing of IPv6 host literals in net/url

5 months agoEPSS 1%
UNKNOWNGo

Unexpected session resumption in crypto/tls

Unexpected session resumption in crypto/tls

6 months agoEPSS 1%
UNKNOWNGo

Arbitrary file write using cgo pkg-config directive in cmd/go

Arbitrary file write using cgo pkg-config directive in cmd/go

6 months agoEPSS 1%
UNKNOWNGo

Memory exhaustion in query parameter parsing in net/url

Memory exhaustion in query parameter parsing in net/url

6 months agoEPSS 2%
UNKNOWNGo

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

8 months agoEPSS 0%
UNKNOWNGo

Unbounded allocation when parsing GNU sparse map in archive/tar

Unbounded allocation when parsing GNU sparse map in archive/tar

9 months agoEPSS 0%
UNKNOWNGo

Stack exhaustion in Parse in go/build/constraint

Stack exhaustion in Parse in go/build/constraint

1 year agoEPSS 1%
UNKNOWNGo

Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl

Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl

2 years agoEPSS 2%

Tooling for Go

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9hexMavenNuGetPyPIRubyGemscrates.ionpm