product of golang

go

18 thingsrelated by NVD
Severity

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello
CVE-2026-42505
Severity medium
net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42499
Severity high
golang: Go os.Root: Symlink following vulnerability allows directory traversal
CVE-2026-39822
Severity high
net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39820
Severity high
net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-33814
Severity high
net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-33811
Severity high
crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
CVE-2026-33810
Severity high
crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
CVE-2026-32283
Severity high
crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
CVE-2026-32280
Severity high
cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
CVE-2026-27140
Severity high
crypto/x509: Incorrect enforcement of email constraints in crypto/x509
CVE-2026-27137
Severity high
net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-25679
Severity high
cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy
CVE-2025-61732
Severity high
cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive
CVE-2025-61731
Severity high
golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-61726
Severity high
encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1
CVE-2025-58185
Severity medium
net/url: Insufficient validation of bracketed IPv6 hostnames in net/url
CVE-2025-47912
Severity medium
github.com/traefik/traefik: net/http2: Traefik: Denial of Service via HTTP/2 Rapid Reset technique
CVE-2023-54365
Severity high