golang
44 known vulnerabilities affecting golang products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-44487 | Act now | 100.0% | 7.5 | ● | The HTTP/2 protocol allows a denial of service (server resource consumption) bec… |
| CVE-2026-42508 | Medium | 7.3% | 9.1 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked… | |
| CVE-2025-61726 | Medium | 2.2% | 7.5 | The net/url package does not set a limit on the number of query parameters in a … | |
| CVE-2026-33811 | Medium | 0.8% | 7.5 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can… | |
| CVE-2026-42499 | Medium | 0.8% | 7.5 | Pathological inputs could cause DoS through consumePhrase when parsing an email … | |
| CVE-2026-39820 | Medium | 0.8% | 7.5 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were … | |
| CVE-2026-33814 | Medium | 0.8% | 7.5 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of… | |
| CVE-2026-25679 | Medium | 0.7% | 7.5 | url.Parse insufficiently validated the host/authority component and accepted som… | |
| CVE-2026-39821 | Medium | 0.7% | 9.6 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t… | |
| CVE-2026-27140 | Medium | 0.7% | 8.8 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code sm… | |
| CVE-2026-32283 | Medium | 0.6% | 7.5 | If one side of the TLS connection sends multiple key update messages post-handsh… | |
| CVE-2026-39830 | Medium | 0.6% | 9.1 | A malicious SSH peer could send unsolicited global request responses to fill an … | |
| CVE-2026-32280 | Medium | 0.6% | 7.5 | During chain building, the amount of work that is done is not correctly limited … | |
| CVE-2026-27137 | Medium | 0.6% | 7.5 | When verifying a certificate chain which contains a certificate containing multi… | |
| CVE-2026-39832 | Medium | 0.6% | 9.1 | When adding a key to a remote agent constraint extensions such as restrict-desti… | |
| CVE-2025-61731 | Medium | 0.6% | 7.8 | Building a malicious file with cmd/go can cause can cause a write to an attacker… | |
| CVE-2026-27143 | Medium | 0.5% | 9.8 | Arithmetic over induction variables in loops were not correctly checked for unde… | |
| CVE-2026-39834 | Medium | 0.5% | 9.1 | When writing data larger than 4GB in a single Write call on an SSH channel, an i… | |
| CVE-2026-46595 | Medium | 0.5% | 10.0 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server … | |
| CVE-2025-61732 | Medium | 0.5% | 8.6 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smu… | |
| CVE-2026-46597 | Medium | 0.5% | 7.5 | An incorrectly placed cast from bytes to int allowed for server-side panic in th… | |
| CVE-2026-39829 | Medium | 0.5% | 7.5 | The RSA and DSA public key parsers did not enforce size limits on key parameters… | |
| CVE-2026-39831 | Medium | 0.4% | 9.1 | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@open… | |
| CVE-2026-39833 | Medium | 0.4% | 9.1 | The in-memory keyring returned by NewKeyring() silently accepted keys with the C… | |
| CVE-2026-56855 | Medium | 0.4% | 7.5 | Previously, after a channel has been established, a malicious peer could send cr… | |
| CVE-2026-32281 | Medium | 0.4% | 7.5 | Validating certificate chains which use policies is unexpectedly inefficient whe… | |
| CVE-2026-33810 | Medium | 0.3% | 8.2 | When verifying a certificate chain containing excluded DNS constraints, these co… | |
| CVE-2026-78662 | Medium | 0.3% | 7.5 | Previously, a channel registered in the mux's chanList is not usable until it is… | |
| CVE-2026-27144 | Medium | 0.3% | 7.1 | The compiler is meant to unwrap pointers which are the operands of a memory move… | |
| CVE-2026-39822 | Medium | 0.2% | 7.8 | On Unix systems, opening a file in an os.Root improperly follows symlinks to loc… | |
| CVE-2026-42503 | Medium | 0.2% | 8.8 | gopls by default communicates via pipe. However, -port and -listen flags are sup… | |
| CVE-2026-39835 | Low | 0.5% | 5.3 | SSH servers which use CertChecker as a public key callback without setting IsUse… | |
| CVE-2026-46598 | Low | 0.4% | 5.3 | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malfor… | |
| CVE-2026-42505 | Low | 0.4% | 5.3 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive… | |
| CVE-2026-39828 | Low | 0.4% | 6.3 | When an SSH server authentication callback returned PartialSuccessError with non… | |
| CVE-2026-25680 | Low | 0.3% | 6.5 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denia… | |
| CVE-2026-32282 | Low | 0.3% | 6.4 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod… | |
| CVE-2026-32288 | Low | 0.3% | 5.5 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously… | |
| CVE-2026-32289 | Low | 0.3% | 6.1 | Context was not properly tracked across template branches for JS template litera… | |
| CVE-2026-39827 | Low | 0.3% | 6.5 | An authenticated SSH client that repeatedly opened channels which were rejected … | |
| CVE-2026-42506 | Low | 0.2% | 6.1 | Parsing arbitrary HTML which is then rendered using Render can result in an unex… | |
| CVE-2026-25681 | Low | 0.2% | 6.1 | Parsing arbitrary HTML which is then rendered using Render can result in an unex… | |
| CVE-2026-27136 | Low | 0.2% | 6.1 | Parsing arbitrary HTML which is then rendered using Render can result in an unex… | |
| CVE-2026-42502 | Low | 0.2% | 6.1 | Parsing arbitrary HTML which is then rendered using Render can result in an unex… |