Go incidents
Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
sigstore-go fails to check signature timestamps against a signing key's validity period
sigstore-go fails to check signature timestamps against a signing key's validity period
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
Wings exposes node configuration secrets through egg configuration-file templating
Wings exposes node configuration secrets through egg configuration-file templating
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Logging operator has Fluentd configuration injection that allows remote code execution
Logging operator has Fluentd configuration injection that allows remote code execution
ZITADEL Users Can Self-Verify Email/Phone via API
ZITADEL Users Can Self-Verify Email/Phone via API
netfoil: Incorrect block responses could lead to localhost traffic
netfoil: Incorrect block responses could lead to localhost traffic
prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Hardlink path traversal during tar extraction in oras.land/oras-go
Hardlink path traversal during tar extraction in oras.land/oras-go
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
sigstore-go has a multi-log threshold bypass via single compromised log
sigstore-go has a multi-log threshold bypass via single compromised log
Invoking Encrypted Client Hello privacy leak in crypto/tls
Invoking Encrypted Client Hello privacy leak in crypto/tls
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
Arbitrary inputs are included in errors without any escaping in net/textproto
Arbitrary inputs are included in errors without any escaping in net/textproto
Inefficient candidate hostname parsing in crypto/x509
Inefficient candidate hostname parsing in crypto/x509
Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Integer Overflow in Decoder
iskorotkov/avro: Integer Overflow in Decoder
iskorotkov/avro: CPU Exhaustion in Decoder
iskorotkov/avro: CPU Exhaustion in Decoder
Panic in Dial and LookupPort when handling NUL byte on Windows in net
Panic in Dial and LookupPort when handling NUL byte on Windows in net
Crash when handling long CNAME response in net
Crash when handling long CNAME response in net
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
Inefficient policy validation in crypto/x509
Inefficient policy validation in crypto/x509
Unexpected work during chain building in crypto/x509
Unexpected work during chain building in crypto/x509
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Incorrect parsing of IPv6 host literals in net/url
Incorrect parsing of IPv6 host literals in net/url
Unexpected session resumption in crypto/tls
Unexpected session resumption in crypto/tls
Arbitrary file write using cgo pkg-config directive in cmd/go
Arbitrary file write using cgo pkg-config directive in cmd/go
Memory exhaustion in query parameter parsing in net/url
Memory exhaustion in query parameter parsing in net/url
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
Unbounded allocation when parsing GNU sparse map in archive/tar
Unbounded allocation when parsing GNU sparse map in archive/tar
Stack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl
Memory leak in github.com/golang-fips/openssl/v2 and github.com/microsoft/go-crypto-openssl
Tooling for Go
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.