Go incidents

Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

CRITICALGo

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

1 day ago
MODERATEGo

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

1 day ago
MODERATEGo

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

1 day ago
LOWGo

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

1 day ago
MEDIUMGo

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

1 day ago
HIGHGo

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding

4 days ago
HIGHGo

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

4 days ago
HIGHGo

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS

4 days ago
MEDIUMGo

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

5 days ago
HIGHGo

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution

5 days ago
MODERATEGo

Velero vulnerable to file path traversal when extracting from backup's tarball

Velero vulnerable to file path traversal when extracting from backup's tarball

5 days ago
MODERATEGo

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access

5 days ago
MEDIUMGo

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

5 days ago
HIGHGo

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

5 days ago
MEDIUMGo

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

5 days ago
HIGHGo

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header

5 days ago
MEDIUMGo

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

5 days ago
MEDIUMGo

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

5 days ago
HIGHGo

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

5 days ago
MEDIUMGo

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

5 days ago
MEDIUMGo

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

5 days ago
HIGHGo

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

5 days ago
HIGHGo

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database

5 days ago
MODERATEGo

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS

6 days ago
UNKNOWNGo

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel

6 days ago
LOWGo

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

6 days ago
MODERATEGo

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

6 days ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

1 week ago
HIGHGo

moby/go-archive: Crafted tar archive can write outside the extraction directory

moby/go-archive: Crafted tar archive can write outside the extraction directory

1 week ago
UNKNOWNGo

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

1 week ago
UNKNOWNGo

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings

1 week ago
UNKNOWNGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent

1 week ago
UNKNOWNGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

1 week ago
UNKNOWNGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite

1 week ago
UNKNOWNGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

1 week ago
UNKNOWNGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs

1 week ago
UNKNOWNGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket

1 week ago
UNKNOWNGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission

1 week ago
UNKNOWNGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin

1 week ago
UNKNOWNGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima

1 week ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

1 week ago
UNKNOWNGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

1 week ago
UNKNOWNGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server

1 week ago
UNKNOWNGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

1 week ago
UNKNOWNGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp

1 week ago
UNKNOWNGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket

1 week ago
UNKNOWNGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission

1 week ago
UNKNOWNGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server

1 week ago
UNKNOWNGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs

1 week ago
UNKNOWNGo

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings

1 week ago
UNKNOWNGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission

1 week ago
UNKNOWNGo

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs

1 week ago
UNKNOWNGo

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator

1 week ago
UNKNOWNGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs

1 week ago
UNKNOWNGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin

1 week ago
UNKNOWNGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner

1 week ago
UNKNOWNGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

1 week ago
UNKNOWNGo

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil

1 week ago
UNKNOWNGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner

1 week ago
UNKNOWNGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer

1 week ago
UNKNOWNGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api

1 week ago
UNKNOWNGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer

1 week ago
UNKNOWNGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer

1 week ago
UNKNOWNGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent

1 week ago
UNKNOWNGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik

1 week ago
UNKNOWNGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api

1 week ago
UNKNOWNGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli

1 week ago
UNKNOWNGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik

1 week ago
UNKNOWNGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api

1 week ago
UNKNOWNGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin

1 week ago
UNKNOWNGo

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api

1 week ago
UNKNOWNGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend

1 week ago
UNKNOWNGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner

1 week ago
UNKNOWNGo

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api

1 week ago
UNKNOWNGo

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer

1 week ago
UNKNOWNGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli

1 week ago
UNKNOWNGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs

1 week ago
UNKNOWNGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs

1 week ago
UNKNOWNGo

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td

1 week ago
UNKNOWNGo

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

LDAP injection via unescaped username in github.com/hyperledger/fabric-ca

1 week ago
UNKNOWNGo

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3

1 week ago
UNKNOWNGo

Worktree operations may follow symlinks in github.com/go-git/go-git

Worktree operations may follow symlinks in github.com/go-git/go-git

1 week ago
UNKNOWNGo

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi

1 week ago
UNKNOWNGo

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk

1 week ago
UNKNOWNGo

Path traversal via crafted reference names in github.com/go-git/go-git

Path traversal via crafted reference names in github.com/go-git/go-git

1 week ago
UNKNOWNGo

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone

1 week ago
UNKNOWNGo

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3

1 week ago
UNKNOWNGo

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4

1 week ago
UNKNOWNGo

Authorization bypass in serve restic in github.com/rclone/rclone

Authorization bypass in serve restic in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Path traversal in serve s3 in github.com/rclone/rclone

Path traversal in serve s3 in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Unsafe file permission restoration from metadata in github.com/rclone/rclone

Unsafe file permission restoration from metadata in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Arbitrary file write via --links symlinks in github.com/rclone/rclone

Arbitrary file write via --links symlinks in github.com/rclone/rclone

1 week ago
UNKNOWNGo

FTP command injection via custom encoding in github.com/rclone/rclone

FTP command injection via custom encoding in github.com/rclone/rclone

1 week ago
MEDIUMGo

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data

1 week ago
UNKNOWNGo

Path traversal via crafted archive paths in github.com/rclone/rclone

Path traversal via crafted archive paths in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi

1 week ago
UNKNOWNGo

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Path traversal via local backend encoding in github.com/rclone/rclone

Path traversal via local backend encoding in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Command execution via PowerShell smart quotes in github.com/rclone/rclone

Command execution via PowerShell smart quotes in github.com/rclone/rclone

1 week ago
UNKNOWNGo

Path traversal in serve restic in github.com/rclone/rclone

Path traversal in serve restic in github.com/rclone/rclone

1 week ago
UNKNOWNGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList

1 week ago
UNKNOWNGo

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

Cross-forge account takeover on login in codefloe.com/crowci/crow/v6

1 week ago
UNKNOWNGo

Stale blob descriptor cache invalidation in github.com/distribution/distribution

Stale blob descriptor cache invalidation in github.com/distribution/distribution

1 week ago
UNKNOWNGo

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env

1 week ago
UNKNOWNGo

Watch API authorization bypass in go.etcd.io/etcd/server/v3

Watch API authorization bypass in go.etcd.io/etcd/server/v3

1 week ago
UNKNOWNGo

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp

1 week ago
UNKNOWNGo

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

Authorization bypass via double-encoded paths in github.com/valyala/fasthttp

1 week ago
UNKNOWNGo

Integer overflow in BTF parsing in github.com/cilium/ebpf

Integer overflow in BTF parsing in github.com/cilium/ebpf

1 week ago
UNKNOWNGo

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

1 week ago
MODERATEGo

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

1 week ago
UNKNOWNGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet

1 week ago
UNKNOWNGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt

1 week ago
UNKNOWNGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend

1 week ago
UNKNOWNGo

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli

1 week ago
UNKNOWNGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows

1 week ago
UNKNOWNGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik

1 week ago
UNKNOWNGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook

1 week ago
UNKNOWNGo

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate

1 week ago
UNKNOWNGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh

1 week ago
UNKNOWNGo

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go

1 week ago
UNKNOWNGo

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai

1 week ago
UNKNOWNGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik

1 week ago
UNKNOWNGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner

1 week ago
UNKNOWNGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server

1 week ago
UNKNOWNGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer

1 week ago
UNKNOWNGo

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

1 week ago
UNKNOWNGo

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole

1 week ago
UNKNOWNGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel

1 week ago
UNKNOWNGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission

1 week ago
UNKNOWNGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go

1 week ago
UNKNOWNGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings

1 week ago
UNKNOWNGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

1 week ago
UNKNOWNGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend

1 week ago
UNKNOWNGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer

1 week ago
UNKNOWNGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer

1 week ago
UNKNOWNGo

goshs has a Path Traversal issue in github.com/patrickhener/goshs

goshs has a Path Traversal issue in github.com/patrickhener/goshs

1 week ago
UNKNOWNGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf

1 week ago
UNKNOWNGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList

1 week ago
UNKNOWNGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings

1 week ago
UNKNOWNGo

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

Gophish contains a denial of service vulnerability in github.com/gophish/gophish

1 week ago
CRITICALGo

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

1 week ago
HIGHGo

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

1 week ago
MODERATEGo

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

1 week ago
CRITICALGo

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

1 week ago
MODERATEGo

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

1 week ago
MODERATEGo

New API: Admin can reset passkeys for same-level or higher-privileged users

New API: Admin can reset passkeys for same-level or higher-privileged users

github.com/QuantumNous/new-api: 0.9.1.3 → 1.0.0-rc.7

1 week ago
MODERATEGo

uniget CLI has an EDITOR Command Injection

uniget CLI has an EDITOR Command Injection

1 week ago
HIGHGo

New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API: Integer overflow in quota billing yields negative charges (self-crediting)

1 week ago
MODERATEGo

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability

1 week ago
UNKNOWNGo

Excessive memory allocation during VP8L decoding in golang.org/x/image

Excessive memory allocation during VP8L decoding in golang.org/x/image

1 week ago
MODERATEGo

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter

1 week ago
HIGHGo

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts

1 week ago
CRITICALGo

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

1 week ago
UNKNOWNGo

Fix Javascript regexp context tracking in html/template

Fix Javascript regexp context tracking in html/template

1 week ago
HIGHGo

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

1 week ago
UNKNOWNGo

Add recursion depth guard during decode in encoding/xml

Add recursion depth guard during decode in encoding/xml

1 week ago
UNKNOWNGo

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

1 week ago
UNKNOWNGo

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

1 week ago
UNKNOWNGo

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

1 week ago
UNKNOWNGo

Avoid quadratic complexity in resolvePath in net/url

Avoid quadratic complexity in resolvePath in net/url

1 week ago
UNKNOWNGo

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

1 week ago
UNKNOWNGo

Limit handshake messages we are willing to accept post-handshake in crypto/tls

Limit handshake messages we are willing to accept post-handshake in crypto/tls

1 week ago
HIGHGo

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint

1 week ago
HIGHGo

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

1 week ago
UNKNOWNGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Unauthenticated backend instantiation in github.com/rclone/rclone

Unauthenticated backend instantiation in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone

2 weeks ago
UNKNOWNGo

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

2 weeks ago
UNKNOWNGo

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

2 weeks ago
HIGHGo

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle

2 weeks ago
UNKNOWNGo

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

2 weeks ago
UNKNOWNGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall

2 weeks ago
UNKNOWNGo

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik

2 weeks ago
UNKNOWNGo

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph

2 weeks ago
UNKNOWNGo

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph

2 weeks ago
UNKNOWNGo

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph

2 weeks ago
UNKNOWNGo

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

2 weeks ago
HIGHGo

go-git: Malicious reference names may modify files outside the reference storage

go-git: Malicious reference names may modify files outside the reference storage

2 weeks ago
HIGHGo

go-git: Worktree operations may follow symlinks

go-git: Worktree operations may follow symlinks

2 weeks ago
HIGHGo

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

2 weeks ago
MEDIUMGo

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

2 weeks ago
HIGHGo

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

2 weeks ago
LOWGo

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

2 weeks ago
MODERATEGo

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

2 weeks ago
MODERATEGo

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

2 weeks ago
HIGHGo

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

2 weeks ago
HIGHGo

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

2 weeks ago
HIGHGo

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

2 weeks ago
CRITICALGo

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

2 weeks ago
MODERATEGo

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

2 weeks ago
MEDIUMGo

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

2 weeks ago
MEDIUMGo

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect

2 weeks ago
HIGHGo

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

2 weeks ago
HIGHGo

rclone: Local Encoding Path Traversal

rclone: Local Encoding Path Traversal

2 weeks ago
HIGHGo

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

2 weeks ago
HIGHGo

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

2 weeks ago
MEDIUMGo

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

2 weeks ago
MEDIUMGo

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

rclone: Verbose Stack Trace Disclosure in RC API Error Responses

2 weeks ago
HIGHGo

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

2 weeks ago
MEDIUMGo

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

2 weeks ago
HIGHGo

rclone: Incomplete path validation allows backend root escape in serve restic

rclone: Incomplete path validation allows backend root escape in serve restic

2 weeks ago
HIGHGo

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

2 weeks ago
CRITICALGo

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

2 weeks ago
HIGHGo

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

2 weeks ago
MODERATEGo

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

2 weeks ago
MEDIUMGo

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

3 weeks agoEPSS 0%
HIGHGo

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM

3 weeks agoEPSS 0%
CRITICALGo

Wings exposes node configuration secrets through egg configuration-file templating

Wings exposes node configuration secrets through egg configuration-file templating

3 weeks agoEPSS 0%
HIGHGo

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

3 weeks agoEPSS 0%
HIGHGo

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service

3 weeks agoEPSS 0%
MODERATEGo

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

3 weeks agoEPSS 0%
MEDIUMGo

sigstore-go fails to check signature timestamps against a signing key's validity period

sigstore-go fails to check signature timestamps against a signing key's validity period

3 weeks agoEPSS 0%
HIGHGo

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

3 weeks agoEPSS 0%
HIGHGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

3 weeks agoEPSS 0%
MEDIUMGo

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

3 weeks agoEPSS 0%
MODERATEGo

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

3 weeks agoEPSS 0%
MEDIUMGo

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

3 weeks agoEPSS 0%
CRITICALGo

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

3 weeks agoEPSS 1%
HIGHGo

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

3 weeks agoEPSS 0%
HIGHGo

netfoil: Incorrect block responses could lead to localhost traffic

netfoil: Incorrect block responses could lead to localhost traffic

3 weeks ago
CRITICALGo

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

3 weeks agoEPSS 0%
CRITICALGo

Logging operator has Fluentd configuration injection that allows remote code execution

Logging operator has Fluentd configuration injection that allows remote code execution

3 weeks agoEPSS 0%
HIGHGo

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

3 weeks agoEPSS 0%
HIGHGo

openhole-server vulnerable to path traversal via URL-decoded request path

openhole-server vulnerable to path traversal via URL-decoded request path

4 weeks ago
HIGHGo

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode

4 weeks ago
MODERATEGo

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

4 weeks ago
MEDIUMGo

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

4 weeks ago
HIGHGo

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

4 weeks ago
MEDIUMGo

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

4 weeks ago
MEDIUMGo

goshs has a Path Traversal issue

goshs has a Path Traversal issue

4 weeks ago
HIGHGo

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

4 weeks ago
HIGHGo

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

4 weeks ago
MODERATEGo

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

4 weeks agoEPSS 0%
HIGHGo

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

4 weeks ago
HIGHGo

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel

4 weeks ago
MODERATEGo

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

4 weeks agoEPSS 0%
HIGHGo

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

4 weeks ago
HIGHGo

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

4 weeks ago
HIGHGo

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

4 weeks ago
MEDIUMGo

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

4 weeks ago
MEDIUMGo

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

4 weeks ago
UNKNOWNGo

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go

4 weeks agoEPSS 0%
UNKNOWNGo

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

4 weeks ago
UNKNOWNGo

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

4 weeks ago
UNKNOWNGo

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2

4 weeks ago
UNKNOWNGo

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

4 weeks ago
HIGHGo

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

4 weeks ago
UNKNOWNGo

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

4 weeks ago
UNKNOWNGo

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git

4 weeks ago
MEDIUMGo

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

4 weeks ago
UNKNOWNGo

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

4 weeks ago
MODERATEGo

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

4 weeks ago
CRITICALGo

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

4 weeks ago
MEDIUMGo

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

4 weeks ago
UNKNOWNGo

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git

4 weeks ago
UNKNOWNGo

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git

4 weeks ago
MEDIUMGo

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

4 weeks ago
HIGHGo

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

4 weeks ago
HIGHGo

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

4 weeks ago
UNKNOWNGo

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git

4 weeks ago
HIGHGo

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

4 weeks ago
UNKNOWNGo

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm

4 weeks ago
UNKNOWNGo

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel

4 weeks ago
HIGHGo

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

4 weeks ago
HIGHGo

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

4 weeks ago
MEDIUMGo

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

4 weeks ago
UNKNOWNGo

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver

4 weeks ago
MEDIUMGo

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

4 weeks ago
UNKNOWNGo

Hardlink path traversal during tar extraction in oras.land/oras-go

Hardlink path traversal during tar extraction in oras.land/oras-go

4 weeks agoEPSS 0%
UNKNOWNGo

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp

4 weeks ago
UNKNOWNGo

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy

4 weeks ago
HIGHGo

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

4 weeks ago
UNKNOWNGo

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

4 weeks ago
MEDIUMGo

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

4 weeks ago
MEDIUMGo

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

4 weeks ago
MEDIUMGo

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

4 weeks ago
UNKNOWNGo

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy

4 weeks ago
UNKNOWNGo

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk

4 weeks agoEPSS 0%
HIGHGo

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

4 weeks ago
HIGHGo

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

4 weeks ago
HIGHGo

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

4 weeks ago
UNKNOWNGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

4 weeks ago
UNKNOWNGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

4 weeks ago
UNKNOWNGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma

4 weeks ago
UNKNOWNGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

4 weeks ago
MODERATEGo

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

1 month ago
HIGHGo

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

1 month ago
MODERATEGo

kumactl connects to control plane without verifying TLS certificate when no CA is configured

kumactl connects to control plane without verifying TLS certificate when no CA is configured

1 month ago
MODERATEGo

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

1 month ago
HIGHGo

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

1 month agoEPSS 0%
UNKNOWNGo

Infinite loop on invalid input in golang.org/x/text

Infinite loop on invalid input in golang.org/x/text

1 month ago
UNKNOWNGo

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

1 month ago
HIGHGo

sigstore-go has a multi-log threshold bypass via single compromised log

sigstore-go has a multi-log threshold bypass via single compromised log

1 month agoEPSS 0%
UNKNOWNGo

Concourse login flow has an open redirect issue in github.com/concourse/concourse

Concourse login flow has an open redirect issue in github.com/concourse/concourse

1 month ago
UNKNOWNGo

Invoking Encrypted Client Hello privacy leak in crypto/tls

Invoking Encrypted Client Hello privacy leak in crypto/tls

1 month agoEPSS 0%
UNKNOWNGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

1 month ago
MEDIUMGo

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

1 month agoEPSS 0%
HIGHGo

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

1 month ago
HIGHGo

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

1 month agoEPSS 0%
LOWGo

Concourse login flow has an open redirect issue

Concourse login flow has an open redirect issue

1 month ago
CRITICALGo

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

2 months ago
HIGHGo

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

2 months agoEPSS 1%
HIGHGo

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

2 months agoEPSS 1%
HIGHGo

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

2 months ago
MODERATEGo

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

2 months ago
MEDIUMGo

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

2 months agoEPSS 1%
UNKNOWNGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu

2 months ago
UNKNOWNGo

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution

2 months ago
UNKNOWNGo

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy

2 months ago
UNKNOWNGo

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

2 months ago
HIGHGo

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

2 months ago
HIGHGo

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

2 months ago
HIGHGo

Gophish contains a denial of service vulnerability

Gophish contains a denial of service vulnerability

2 months ago
HIGHGo

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

2 months ago
HIGHGo

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

2 months ago
CRITICALGo

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

2 months ago
HIGHGo

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

2 months ago
CRITICALGo

MCP Toolbox for Databases has an Origin Validation Error

MCP Toolbox for Databases has an Origin Validation Error

2 months ago
MEDIUMGo

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

2 months ago
HIGHGo

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

2 months ago
HIGHGo

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

2 months ago
CRITICALGo

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

2 months ago
MEDIUMGo

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

2 months ago
HIGHGo

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

2 months ago
HIGHGo

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

2 months ago
CRITICALGo

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

2 months ago
HIGHGo

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

2 months ago
HIGHGo

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

2 months ago
CRITICALGo

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

2 months ago
HIGHGo

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

2 months ago
HIGHGo

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

2 months ago
HIGHGo

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

2 months ago
HIGHGo

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

2 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

2 months agoEPSS 0%
HIGHGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

2 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

2 months agoEPSS 0%
MEDIUMGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

2 months agoEPSS 0%
MEDIUMGo

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

2 months agoEPSS 0%
MEDIUMGo

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

2 months ago
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

2 months ago
MEDIUMGo

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

2 months agoEPSS 0%
MEDIUMGo

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

2 months ago
MEDIUMGo

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader

2 months ago
UNKNOWNGo

Quadratic complexity in WordDecoder.DecodeHeader in mime

Quadratic complexity in WordDecoder.DecodeHeader in mime

2 months agoEPSS 1%
UNKNOWNGo

Arbitrary inputs are included in errors without any escaping in net/textproto

Arbitrary inputs are included in errors without any escaping in net/textproto

2 months agoEPSS 0%
UNKNOWNGo

Inefficient candidate hostname parsing in crypto/x509

Inefficient candidate hostname parsing in crypto/x509

2 months agoEPSS 1%
HIGHGo

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

2 months ago
UNKNOWNGo

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

3 months ago
UNKNOWNGo

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

3 months ago
UNKNOWNGo

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

3 months ago
UNKNOWNGo

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

3 months ago
UNKNOWNGo

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

3 months ago
UNKNOWNGo

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

3 months ago
UNKNOWNGo

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

3 months ago
UNKNOWNGo

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg

3 months ago
HIGHGo

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

iskorotkov/avro: Denial-of-Service Vulnerability in Decoder

3 months ago
HIGHGo

iskorotkov/avro: CPU Exhaustion in Decoder

iskorotkov/avro: CPU Exhaustion in Decoder

3 months ago
HIGHGo

iskorotkov/avro: Integer Overflow in Decoder

iskorotkov/avro: Integer Overflow in Decoder

3 months ago
MODERATEGo

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

3 months ago
UNKNOWNGo

Quadratic string concatenation in consumePhrase in net/mail

Quadratic string concatenation in consumePhrase in net/mail

3 months ago
UNKNOWNGo

Panic in Dial and LookupPort when handling NUL byte on Windows in net

Panic in Dial and LookupPort when handling NUL byte on Windows in net

3 months agoEPSS 1%
UNKNOWNGo

Crash when handling long CNAME response in net

Crash when handling long CNAME response in net

3 months agoEPSS 1%
UNKNOWNGo

Quadratic string concatentation in consumeComment in net/mail

Quadratic string concatentation in consumeComment in net/mail

3 months ago
HIGHGo

Prometheus Azure AD remote write OAuth client secret exposed via config API

Prometheus Azure AD remote write OAuth client secret exposed via config API

3 months ago
MODERATEGo

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

3 months ago
MODERATEGo

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

3 months ago
HIGHGo

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

4 months ago
CRITICALGo

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

4 months ago
HIGHGo

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

4 months ago
HIGHGo

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

4 months ago
CRITICALGo

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

4 months ago
CRITICALGo

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

4 months ago
CRITICALGo

LXD: Importing a crafted backup leads to project restriction bypass

LXD: Importing a crafted backup leads to project restriction bypass

4 months ago
UNKNOWNGo

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

4 months agoEPSS 0%
UNKNOWNGo

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

4 months agoEPSS 1%
UNKNOWNGo

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

4 months ago
UNKNOWNGo

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

4 months agoEPSS 1%
UNKNOWNGo

Unexpected work during chain building in crypto/x509

Unexpected work during chain building in crypto/x509

4 months agoEPSS 1%
UNKNOWNGo

Inefficient policy validation in crypto/x509

Inefficient policy validation in crypto/x509

4 months agoEPSS 0%
UNKNOWNGo

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile

4 months agoEPSS 0%
HIGHGo

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

4 months ago
CRITICALGo

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

4 months ago
CRITICALGo

Moby has AuthZ plugin bypass when provided oversized request bodies

Moby has AuthZ plugin bypass when provided oversized request bodies

5 months ago
MODERATEGo

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

5 months ago
UNKNOWNGo

Incorrect parsing of IPv6 host literals in net/url

Incorrect parsing of IPv6 host literals in net/url

5 months agoEPSS 1%
UNKNOWNGo

Incorrect enforcement of email constraints in crypto/x509

Incorrect enforcement of email constraints in crypto/x509

5 months ago
UNKNOWNGo

Unexpected session resumption in crypto/tls

Unexpected session resumption in crypto/tls

6 months agoEPSS 1%
UNKNOWNGo

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format in github.com/opentofu/opentofu

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format in github.com/opentofu/opentofu

6 months ago
UNKNOWNGo

Client DoS via malformed server response in github.com/theupdateframework/go-tuf

Client DoS via malformed server response in github.com/theupdateframework/go-tuf

6 months ago
UNKNOWNGo

Handshake messages may be processed at the incorrect encryption level in crypto/tls

Handshake messages may be processed at the incorrect encryption level in crypto/tls

6 months ago
UNKNOWNGo

Excessive CPU consumption when building archive index in archive/zip

Excessive CPU consumption when building archive index in archive/zip

6 months ago
UNKNOWNGo

Arbitrary file write using cgo pkg-config directive in cmd/go

Arbitrary file write using cgo pkg-config directive in cmd/go

6 months agoEPSS 1%
UNKNOWNGo

Memory exhaustion in query parameter parsing in net/url

Memory exhaustion in query parameter parsing in net/url

6 months agoEPSS 2%
UNKNOWNGo

Open redirect vulnerability in the RedirectSlashes middleware in github.com/go-chi/chi

Open redirect vulnerability in the RedirectSlashes middleware in github.com/go-chi/chi

7 months ago
HIGHGo

go-tuf affected by client DoS via malformed server response

go-tuf affected by client DoS via malformed server response

7 months ago
MEDIUMGo

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format

OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format

7 months ago
UNKNOWNGo

Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama

Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama

7 months ago
MEDIUMGo

chi has an open redirect vulnerability in the RedirectSlashes middleware

chi has an open redirect vulnerability in the RedirectSlashes middleware

7 months ago
HIGHGo

Cosign verification accepts any valid Rekor entry under certain conditions

Cosign verification accepts any valid Rekor entry under certain conditions

7 months ago
UNKNOWNGo

Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign

Cosign verification accepts any valid Rekor entry under certain conditions in github.com/sigstore/cosign

7 months ago
CRITICALGo

Ollama Platform has missing authentication enabling attackers to perform model management operations

Ollama Platform has missing authentication enabling attackers to perform model management operations

8 months ago
UNKNOWNGo

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

8 months agoEPSS 0%
UNKNOWNGo

DoS risk due to unrestricted RAR dictionary sizes in github.com/nwaples/rardecode

DoS risk due to unrestricted RAR dictionary sizes in github.com/nwaples/rardecode

9 months ago
UNKNOWNGo

Panic occurs when queuing undecryptable packets after handshake completion in github.com/quic-go/quic-go

Panic occurs when queuing undecryptable packets after handshake completion in github.com/quic-go/quic-go

9 months ago
UNKNOWNGo

Panic when validating certificates with DSA public keys in crypto/x509

Panic when validating certificates with DSA public keys in crypto/x509

10 months ago
UNKNOWNGo

Unbounded allocation when parsing GNU sparse map in archive/tar

Unbounded allocation when parsing GNU sparse map in archive/tar

10 months agoEPSS 0%
UNKNOWNGo

Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd

Repository Credentials Race Condition Crashes Argo CD Server in github.com/argoproj/argo-cd

10 months ago
MEDIUMGo

rardecode: DoS risk due to unrestricted RAR dictionary sizes

rardecode: DoS risk due to unrestricted RAR dictionary sizes

10 months ago
HIGHGo

quic-go: Panic occurs when queuing undecryptable packets after handshake completion

quic-go: Panic occurs when queuing undecryptable packets after handshake completion

10 months ago
HIGHGo

Repository Credentials Race Condition Crashes Argo CD Server

Repository Credentials Race Condition Crashes Argo CD Server

10 months ago
UNKNOWNGo

Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure

Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure

0 years ago
HIGHGo

go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data

go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data

1 year ago
UNKNOWNGo

Host header injection which leads to open redirect in RedirectSlashes in github.com/go-chi/chi

Host header injection which leads to open redirect in RedirectSlashes in github.com/go-chi/chi

1 year ago
MODERATEGo

chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes

chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes

1 year ago
UNKNOWNGo

Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server

Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server

1 year ago
UNKNOWNGo

Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server

Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server

1 year ago
MEDIUMGo

Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost fails to properly enforce access control restrictions for System Manager roles

1 year ago
MEDIUMGo

Mattermost fails to properly enforce access controls for guest users

Mattermost fails to properly enforce access controls for guest users

1 year ago
UNKNOWNGo

Query smuggling in ch-go library in github.com/ClickHouse/ch-go

Query smuggling in ch-go library in github.com/ClickHouse/ch-go

1 year ago
MODERATEGo

CVE-2025-1386- Query smuggling in ch-go library

CVE-2025-1386- Query smuggling in ch-go library

1 year ago
UNKNOWNGo

MinIO performs incomplete signature validation for unsigned-trailer uploads in github.com/minio/minio

MinIO performs incomplete signature validation for unsigned-trailer uploads in github.com/minio/minio

1 year ago
HIGHGo

MinIO performs incomplete signature validation for unsigned-trailer uploads

MinIO performs incomplete signature validation for unsigned-trailer uploads

1 year ago
UNKNOWNGo

Excessive memory allocation during header parsing in github.com/golang-jwt/jwt

Excessive memory allocation during header parsing in github.com/golang-jwt/jwt

1 year ago
UNKNOWNGo

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

1 year ago
MEDIUMGo

Kubernetes kube-apiserver Vulnerable to Race Condition

Kubernetes kube-apiserver Vulnerable to Race Condition

1 year ago
UNKNOWNGo

Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

1 year ago
UNKNOWNGo

Vitess allows HTML injection in /debug/querylogz and /debug/env in vitess.io/vitess

Vitess allows HTML injection in /debug/querylogz and /debug/env in vitess.io/vitess

1 year ago
UNKNOWNGo

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

1 year ago
HIGHGo

Vitess allows HTML injection in /debug/querylogz & /debug/env

Vitess allows HTML injection in /debug/querylogz & /debug/env

1 year ago
UNKNOWNGo

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

1 year ago
CRITICALGo

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

1 year ago
UNKNOWNGo

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8 in github.com/opentofu/opentofu

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8 in github.com/opentofu/opentofu

1 year ago
MEDIUMGo

Buildah allows arbitrary directory mount

Buildah allows arbitrary directory mount

1 year ago
MEDIUMGo

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8

OpenTofu potential leaking of secret variable values when using static evaluation in v1.8

1 year ago
CRITICALGo

OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer

OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer

1 year ago
UNKNOWNGo

Buffer Overflow vulnerability in osrg gobgp in github.com/osrg/gobgp

Buffer Overflow vulnerability in osrg gobgp in github.com/osrg/gobgp

1 year ago
UNKNOWNGo

Stack exhaustion in Parse in go/build/constraint

Stack exhaustion in Parse in go/build/constraint

1 year agoEPSS 1%
UNKNOWNGo

Missing Authorization in HashiCorp Consul in github.com/hashicorp/consul

Missing Authorization in HashiCorp Consul in github.com/hashicorp/consul

2 years ago
UNKNOWNGo

Traefik vulnerable to potential DDoS via ACME HTTPChallenge in github.com/traefik/traefik

Traefik vulnerable to potential DDoS via ACME HTTPChallenge in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes

2 years ago
UNKNOWNGo

HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault

HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault

2 years ago
UNKNOWNGo

Traefik routes exposed with an empty TLSOption in github.com/traefik/traefik

Traefik routes exposed with an empty TLSOption in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno

Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno

2 years ago
UNKNOWNGo

Traefik docker container using 100% CPU in github.com/traefik/traefik

Traefik docker container using 100% CPU in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Traefik may display authorization header in the debug logs in github.com/traefik/traefik

Traefik may display authorization header in the debug logs in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass in github.com/traefik/traefik

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections in github.com/hashicorp/consul

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections in github.com/hashicorp/consul

2 years ago
UNKNOWNGo

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

2 years ago
UNKNOWNGo

Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno

Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno

2 years ago
UNKNOWNGo

APM Server vulnerable to Insertion of Sensitive Information into Log File in github.com/elastic/apm-server

APM Server vulnerable to Insertion of Sensitive Information into Log File in github.com/elastic/apm-server

2 years ago
UNKNOWNGo

The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd

The Argo CD web terminal session does not handle the revocation of user permissions properly in github.com/argoproj/argo-cd

2 years ago
HIGHGo

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

2 years ago
MEDIUMGo

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

2 years ago
UNKNOWNGo

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault

2 years ago
UNKNOWNGo

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server

Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server

2 years ago
UNKNOWNGo

Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server

Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server

2 years ago
UNKNOWNGo

APM Server vulnerable to Insertion of Sensitive Information into Log File in github.com/elastic/apm-server

APM Server vulnerable to Insertion of Sensitive Information into Log File in github.com/elastic/apm-server

2 years ago
HIGHGo

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

2 years ago
UNKNOWNGo

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

2 years ago
MEDIUMGo

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

2 years ago
MODERATEGo

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

2 years ago
UNKNOWNGo

Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server

Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server

2 years ago
UNKNOWNGo

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Traefik vulnerable to denial of service with Content-length header in github.com/traefik/traefik

Traefik vulnerable to denial of service with Content-length header in github.com/traefik/traefik

2 years ago
UNKNOWNGo

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences in github.com/argoproj/argo-cd

2 years ago
UNKNOWNGo

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers in github.com/hashicorp/consul

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers in github.com/hashicorp/consul

2 years ago
UNKNOWNGo

Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd

Argo CD's API server does not enforce project sourceNamespaces in github.com/argoproj/argo-cd

2 years ago
MEDIUMGo

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

2 years ago
HIGHGo

Buffer Overflow vulnerability in osrg gobgp

Buffer Overflow vulnerability in osrg gobgp

2 years ago
HIGHGo

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

2 years ago
UNKNOWNGo

Out of memory crash from malicious Helm registry in github.com/argoproj/argo-cd/v2

Out of memory crash from malicious Helm registry in github.com/argoproj/argo-cd/v2

2 years ago
HIGHGo

Argo CD's API server does not enforce project sourceNamespaces

Argo CD's API server does not enforce project sourceNamespaces

2 years ago
MODERATEGo

Traefik affected by HTTP/2 CONTINUATION flood in net/http

Traefik affected by HTTP/2 CONTINUATION flood in net/http

2 years ago
HIGHGo

Traefik vulnerable to denial of service with Content-length header

Traefik vulnerable to denial of service with Content-length header

2 years ago
UNKNOWNGo

Improper handling of node names in JWT claims assertions in github.com/hashicorp/consul

Improper handling of node names in JWT claims assertions in github.com/hashicorp/consul

2 years ago
HIGHGo

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

2 years ago
UNKNOWNGo

Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl

Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl

2 years agoEPSS 2%
UNKNOWNGo

Bypass manifest during application creation in github.com/argoproj/argo-cd/v2

Bypass manifest during application creation in github.com/argoproj/argo-cd/v2

2 years ago
UNKNOWNGo

Brute force protection bypass in github.com/argoproj/argo-cd/v2

Brute force protection bypass in github.com/argoproj/argo-cd/v2

2 years ago
UNKNOWNGo

Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2

Cross-site scripting on application summary component in github.com/argoproj/argo-cd/v2

2 years ago
MEDIUMGo

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

2 years ago
CRITICALGo

Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss

Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss

2 years ago
MEDIUMGo

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

2 years ago
CRITICALGo

Cross-site scripting on application summary component

Cross-site scripting on application summary component

2 years ago
MEDIUMGo

Mattermost leaks details of AD/LDAP groups of a teams

Mattermost leaks details of AD/LDAP groups of a teams

2 years ago
MEDIUMGo

Mattermost denial of service through long emoji value

Mattermost denial of service through long emoji value

2 years ago
MEDIUMGo

Mattermost incorrectly allows access individual posts

Mattermost incorrectly allows access individual posts

2 years ago
UNKNOWNGo

Unauthenticated cross-site scripting in github.com/rancher/apiserver

Unauthenticated cross-site scripting in github.com/rancher/apiserver

2 years ago
MEDIUMGo

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

2 years ago
HIGHGo

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

2 years ago
HIGHGo

Rancher API Server Cross-site Scripting Vulnerability

Rancher API Server Cross-site Scripting Vulnerability

2 years ago
CRITICALGo

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

2 years ago
HIGHGo

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

2 years ago
HIGHGo

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

2 years ago
MEDIUMGo

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

2 years ago
CRITICALGo

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

2 years ago
HIGHGo

Calico Typha denial of service vulnerability

Calico Typha denial of service vulnerability

2 years ago
CRITICALGo

Ingress-nginx path sanitization can be bypassed

Ingress-nginx path sanitization can be bypassed

2 years ago
HIGHGo

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

2 years ago
HIGHGo

Grafana privilege escalation vulnerability

Grafana privilege escalation vulnerability

2 years ago
HIGHGo

HashiCorp Vault Improper Input Validation vulnerability

HashiCorp Vault Improper Input Validation vulnerability

2 years ago
UNKNOWNGo

Denial of service via deflate compression bomb in github.com/crewjam/saml

Denial of service via deflate compression bomb in github.com/crewjam/saml

3 years ago
MEDIUMGo

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers

3 years ago
UNKNOWNGo

Panic when handling invalid request in MITM mode in github.com/elazarl/goproxy

Panic when handling invalid request in MITM mode in github.com/elazarl/goproxy

3 years ago
HIGHGo

goproxy Denial of Service vulnerability

goproxy Denial of Service vulnerability

3 years ago
HIGHGo

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

3 years ago
MEDIUMGo

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

3 years ago
HIGHGo

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

3 years ago
HIGHGo

Kyverno resource with a deletionTimestamp may allow policy circumvention

Kyverno resource with a deletionTimestamp may allow policy circumvention

3 years ago
UNKNOWNGo

Incorrect permissions in github.com/goreleaser/nfpm/v2

Incorrect permissions in github.com/goreleaser/nfpm/v2

3 years ago
MODERATEGo

Kyverno vulnerable due to usage of insecure cipher

Kyverno vulnerable due to usage of insecure cipher

3 years ago
HIGHGo

Ingress-nginx `path` sanitization can be bypassed with newline character

Ingress-nginx `path` sanitization can be bypassed with newline character

3 years ago
HIGHGo

nfpm has incorrect default permissions

nfpm has incorrect default permissions

3 years ago
HIGHGo

crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb

crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb

3 years ago
HIGHGo

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

Consul Server Panic when Ingress and API Gateways Configured with Peering Connections

3 years ago
MEDIUMGo

Grafana vulnerable to Cross-site Scripting

Grafana vulnerable to Cross-site Scripting

3 years ago
HIGHGo

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

3 years ago
HIGHGo

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

3 years ago
UNKNOWNGo

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

3 years ago
MEDIUMGo

Traefik may display authorization header in the debug logs

Traefik may display authorization header in the debug logs

3 years ago
HIGHGo

Traefik routes exposed with an empty TLSOption

Traefik routes exposed with an empty TLSOption

3 years ago
HIGHGo

Missing Authorization in HashiCorp Consul

Missing Authorization in HashiCorp Consul

3 years ago
HIGHGo

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions

3 years ago
UNKNOWNGo

Unbounded recursion in JSON parsing in k8s.io/apimachinery

Unbounded recursion in JSON parsing in k8s.io/apimachinery

3 years ago
CRITICALGo

Improper token validation leading to code execution in Teleport

Improper token validation leading to code execution in Teleport

4 years ago
UNKNOWNGo

Type confusion in github.com/docker/distribution

Type confusion in github.com/docker/distribution

4 years ago
HIGHGo

Calico vulnerable to pod route hijacking

Calico vulnerable to pod route hijacking

4 years ago
HIGHGo

ingress-nginx component for Kubernetes allows file overwrite

ingress-nginx component for Kubernetes allows file overwrite

4 years ago
MEDIUMGo

Kubernetes ingress exposes sensitive information

Kubernetes ingress exposes sensitive information

4 years ago
HIGHGo

Improper Input Validation in k8s.io/ingress-nginx

Improper Input Validation in k8s.io/ingress-nginx

4 years ago
MEDIUMGo

Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico

Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico

4 years ago
MEDIUMGo

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

4 years ago
MEDIUMGo

OCI Manifest Type Confusion Issue

OCI Manifest Type Confusion Issue

4 years ago
MEDIUMGo

Path traversal in Grafana Loki

Path traversal in Grafana Loki

4 years ago

Tooling for Go

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9hexMavenNuGetPackagistPyPIRubyGemscrates.ionpm