← Back

Golang

golang

217 CVEs • 13 products

Products (13)

Click to collapse
Toggle
Go
go
Crypto
crypto
Net
net
Http2
http2
Image
image
Text
text
Ssh
ssh
Tiff
tiff
Networking
networking
Package Ssh
package_ssh
Protobuf
protobuf
H2c
h2c
Hpack
hpack

CVEs (217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Golang
2Fedora
Go
Nov 21, 2024
Sep 6, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
1Golang
1Ssh
Nov 21, 2024
Sep 6, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
1Golang
1Go
Nov 21, 2024
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For he...Show more
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.Show less
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field...Show more
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.Show less
1Golang
1Go
Nov 21, 2024
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.
1Golang
1Go
Oct 20, 2025
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compres...Show more
Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.Show less
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
3.1 LOW· v3
N/A· v2
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during...Show more
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.Show less
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedO...Show more
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.Show less
1Golang
1Go
Nov 21, 2024
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
3Fedoraproject
GolangNetapp
3Cloud Insights Telegraf
FedoraGo
Nov 21, 2024
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.
1Golang
1Go
Mar 6, 2026
Aug 10, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to re...Show more
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.Show less
2Golang
Netapp
2Cloud Insights Telegraf Agent
Go
Nov 21, 2024
Jul 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
3Fedoraproject
GolangNetapp
3Beegfs Csi Driver
FedoraGo
Nov 21, 2024
Jun 23, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
2Fedoraproject
Golang
3Extra Packages For Enterprise Linux
FedoraGo
Nov 21, 2024
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
1Golang
1Go
Nov 21, 2024
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
3Fedoraproject
GolangNetapp
3Fedora
GoKubernetes Monitoring Operator
Nov 21, 2024
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.