vendor

golang

27 thingsrelated by NVD

Its products

go 18 crypto 7 gopls 1 http2 1 net 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46595
Severity critical
golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-42508
Severity critical
crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello
CVE-2026-42505
Severity medium
golang: golang.org/x/tools/gopls: gopls: Arbitrary code execution due to insecure network binding
CVE-2026-42503
Severity high
net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42499
Severity high
golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-39835
Severity high
golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39832
Severity critical
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39830
Severity critical
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39829
Severity high
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39828
Severity high
golang: Go os.Root: Symlink following vulnerability allows directory traversal
CVE-2026-39822
Severity high
golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39821
Severity critical
net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39820
Severity high
net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-33814
Severity high
net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-33811
Severity high
crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
CVE-2026-33810
Severity high
crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
CVE-2026-32283
Severity high
crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
CVE-2026-32280
Severity high
cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names
CVE-2026-27140
Severity high
crypto/x509: Incorrect enforcement of email constraints in crypto/x509
CVE-2026-27137
Severity high
net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-25679
Severity high
cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy
CVE-2025-61732
Severity high
cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive
CVE-2025-61731
Severity high
golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-61726
Severity high
encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1
CVE-2025-58185
Severity medium
net/url: Insufficient validation of bracketed IPv6 hostnames in net/url
CVE-2025-47912
Severity medium
github.com/traefik/traefik: net/http2: Traefik: Denial of Service via HTTP/2 Rapid Reset technique
CVE-2023-54365
Severity high