Golang / GO
173 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-42505 | Invoking Encrypted Client Hello privacy leak in crypto/tls | MEDIUM | 5.3 | Jul 8, 2026 |
| CVE-2026-39822 | Root escape via symlink plus trailing slash in os | HIGH | 7.8 | Jul 8, 2026 |
| CVE-2023-54365 | Traefik - Denial of Service via HTTP/2 Request Handling | HIGH | 8.7 | Jun 23, 2026 |
| CVE-2026-39820 | Quadratic string concatentation in consumeComment in net/mail | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-42501 | Malicious module proxy can bypass checksum database in cmd/go | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-39823 | Bypass of meta content URL escaping causes XSS in html/template | MEDIUM | 6.1 | May 7, 2026 |
| CVE-2026-33811 | Crash when handling long CNAME response in net | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-39826 | Escaper bypass leads to XSS in html/template | MEDIUM | 6.1 | May 7, 2026 |
| CVE-2026-39817 | Invoking "go tool pack" does not sanitize output paths in cmd/go | MEDIUM | 5.9 | May 7, 2026 |
| CVE-2026-39819 | Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go | MEDIUM | 5.3 | May 7, 2026 |
| CVE-2026-42499 | Quadratic string concatenation in consumePhrase in net/mail | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-39825 | ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | MEDIUM | 6.5 | May 7, 2026 |
| CVE-2026-39836 | Panic in Dial and LookupPort when handling NUL byte on Windows in net | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-32280 | Unexpected work during chain building in crypto/x509 | HIGH | 7.5 | Apr 8, 2026 |
| CVE-2026-32281 | Inefficient policy validation in crypto/x509 | HIGH | 7.5 | Apr 8, 2026 |
| CVE-2026-27140 | Code execution vulnerability in SWIG code generation in cmd/go | CRITICAL | 9.0 | Apr 8, 2026 |
| CVE-2026-32283 | Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | HIGH | 7.5 | Apr 8, 2026 |
| CVE-2026-32288 | Unbounded allocation for old GNU sparse in archive/tar | MEDIUM | 5.5 | Apr 8, 2026 |
| CVE-2026-27143 | Missing bound checks can lead to memory corruption in safe Go in cmd/compile | CRITICAL | 9.8 | Apr 8, 2026 |
| CVE-2026-27144 | Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile | HIGH | 8.1 | Apr 8, 2026 |
| CVE-2026-33810 | Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 | HIGH | 8.8 | Apr 8, 2026 |
| CVE-2026-32289 | JsBraceDepth Context Tracking Bugs (XSS) in html/template | MEDIUM | 6.1 | Apr 8, 2026 |
| CVE-2026-32282 | TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | HIGH | 7.8 | Apr 8, 2026 |
| CVE-2026-27142 | URLs in meta content attribute actions are not escaped in html/template | MEDIUM | 6.1 | Mar 6, 2026 |
Showing 1 to 25 of 173 CVEs