Golang
golang
221 CVEs • 13 products
Products (13)
Click to collapseToggle
Products (13)
Click to collapse
CVEs (221)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGolang+1 more4Debian Linux FedoraGo+1 moreJun 17, 2026 Aug 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs. |
5Cloudfoundry DebianFedoraproject+2 more6Cf Deployment Debian LinuxFedora+3 moreJun 17, 2026 Jul 17, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. |
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certi...Show more |
2Fedoraproject Golang2Fedora TextJun 17, 2026 Jun 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide...Show more |
4Debian FedoraprojectGolang+1 more4Cloud Insights Telegraf Debian LinuxFedora+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate. |
2Debian Golang2Debian Linux Package SshJun 17, 2026 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also,...Show more |
2Golang Redhat3Enterprise Linux GoOpenstackNov 21, 2024 Feb 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and...Show more |
2Golang Microsoft13Go Windows 10 1507Windows 10 1607+10 moreJun 17, 2026 Jan 14, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate...Show more |
6Arista DebianFedoraproject+3 more11Cloudvision Portal Debian LinuxDeveloper Tools+8 moreJun 17, 2026 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that veri...Show more |
6Debian FedoraprojectGolang+3 more9Cloud Insights Telegraf Agent Debian LinuxDeveloper Tools+6 moreJun 17, 2026 Sep 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. |
2Debian Golang2Debian Linux GoJun 17, 2026 Aug 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostna...Show more |
2Debian Golang2Crypto Debian LinuxJun 17, 2026 May 22, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleart...Show more |
Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges. |
2Debian Golang2Crypto Debian LinuxJun 17, 2026 May 9, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and go...Show more |
4Debian FedoraprojectGolang+1 more5Debian Linux Developer ToolsEnterprise Linux+2 moreJun 17, 2026 Mar 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a R...Show more |
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection. |
3Debian GolangOpensuse3Debian Linux GoLeapJun 17, 2026 Jan 24, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks. |
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU deni...Show more |
4Debian GolangOpensuse+1 more5Backports Sle Debian LinuxGo+2 moreNov 21, 2024 Dec 14, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' character...Show more |
4Debian GolangOpensuse+1 more5Backports Sle Debian LinuxGo+2 moreNov 21, 2024 Dec 14, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directl...Show more |