Golang / GO
173 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-27139 | FileInfo can escape from a Root in os | LOW | 2.5 | Mar 6, 2026 |
| CVE-2026-25679 | Incorrect parsing of IPv6 host literals in net/url | HIGH | 7.5 | Mar 6, 2026 |
| CVE-2026-27138 | Panic in name constraint checking for malformed certificates in crypto/x509 | MEDIUM | 5.9 | Mar 6, 2026 |
| CVE-2026-27137 | Incorrect enforcement of email constraints in crypto/x509 | HIGH | 7.5 | Mar 6, 2026 |
| CVE-2025-68121 | Unexpected session resumption in crypto/tls | CRITICAL | 10.0 | Feb 5, 2026 |
| CVE-2025-61732 | Potential code smuggling via doc comments in cmd/cgo | HIGH | 8.6 | Feb 5, 2026 |
| CVE-2025-22873 | Improper access to parent directory of root in os | MEDIUM | 5.3 | Feb 4, 2026 |
| CVE-2025-61728 | Excessive CPU consumption when building archive index in archive/zip | HIGH | 7.5 | Jan 28, 2026 |
| CVE-2025-61726 | Memory exhaustion in query parameter parsing in net/url | HIGH | 7.5 | Jan 28, 2026 |
| CVE-2025-61730 | Handshake messages may be processed at the incorrect encryption level in crypto/tls | MEDIUM | 5.3 | Jan 28, 2026 |
| CVE-2025-61731 | Arbitrary file write using cgo pkg-config directive in cmd/go | HIGH | 8.6 | Jan 28, 2026 |
| CVE-2025-68119 | Unexpected code execution when invoking toolchain in cmd/go | HIGH | 7.0 | Jan 28, 2026 |
| CVE-2025-61727 | Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 | MEDIUM | 6.5 | Dec 3, 2025 |
| CVE-2025-61729 | Excessive resource consumption when printing error string for host certificate validation in crypto/x509 | HIGH | 7.5 | Dec 2, 2025 |
| CVE-2025-61724 | Excessive CPU consumption in Reader.ReadResponse in net/textproto | MEDIUM | 5.3 | Oct 29, 2025 |
| CVE-2025-58188 | Panic when validating certificates with DSA public keys in crypto/x509 | HIGH | 7.5 | Oct 29, 2025 |
| CVE-2025-58185 | Parsing DER payload can cause memory exhaustion in encoding/asn1 | MEDIUM | 5.3 | Oct 29, 2025 |
| CVE-2025-47912 | Insufficient validation of bracketed IPv6 hostnames in net/url | MEDIUM | 5.3 | Oct 29, 2025 |
| CVE-2025-61723 | Quadratic complexity when parsing some invalid inputs in encoding/pem | HIGH | 7.5 | Oct 29, 2025 |
| CVE-2025-58189 | ALPN negotiation error contains attacker controlled information in crypto/tls | MEDIUM | 5.3 | Oct 29, 2025 |
| CVE-2025-58187 | Quadratic complexity when checking name constraints in crypto/x509 | HIGH | 7.5 | Oct 29, 2025 |
| CVE-2025-47906 | Unexpected paths returned from LookPath in os/exec | MEDIUM | 6.5 | Sep 18, 2025 |
| CVE-2025-47907 | Incorrect results returned from Rows.Scan in database/sql | HIGH | 7.0 | Aug 7, 2025 |
| CVE-2025-4674 | Unexpected command execution in untrusted VCS repositories in cmd/go | HIGH | 8.6 | Jul 29, 2025 |
| CVE-2025-0913 | Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall | MEDIUM | 5.5 | Jun 11, 2025 |
Showing 26 to 50 of 173 CVEs