VendorsGolanggoall versions
Vulnerabilities

Golang Go

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

174CVEs
CVE-2023-45284
Incorrect detection of reserved device names on Windows in path/filepath
Published 2023-11-09 · Modified
5.3EPSS 0.009
CVE-2023-24532
Incorrect calculation on P256 curves in crypto/internal/nistec
Published 2023-03-08 · Modified
5.3EPSS 0.008
CVE-2025-61724
Excessive CPU consumption in Reader.ReadResponse in net/textproto
Published 2025-10-29 · Analyzed
5.3EPSS 0.005
CVE-2025-58185
Parsing DER payload can cause memory exhaustion in encoding/asn1
Published 2025-10-29 · Analyzed
5.3EPSS 0.005
CVE-2025-58189
ALPN negotiation error contains attacker controlled information in crypto/tls
Published 2025-10-29 · Analyzed
5.3EPSS 0.004
CVE-2025-47912
Insufficient validation of bracketed IPv6 hostnames in net/url
Published 2025-10-29 · Analyzed
5.3EPSS 0.004
CVE-2026-39825
ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
Published 2026-05-07 · Analyzed
5.3EPSS 0.004
CVE-2026-42505
Invoking Encrypted Client Hello privacy leak in crypto/tls
Published 2026-07-08 · Analyzed
5.3EPSS 0.004
CVE-2025-61730
Handshake messages may be processed at the incorrect encryption level in crypto/tls
Published 2026-01-28 · Analyzed
5.3EPSS 0.003
CVE-2026-39819
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Published 2026-05-07 · Analyzed
5.3EPSS 0.001
CVE-2014-7189
crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.
Published 2014-10-07 · Modified
4.3EPSS 0.014
CVE-2025-22873
Improper access to parent directory of root in os
Published 2026-02-04 · Analyzed
3.8EPSS 0.002
CVE-2022-30629
Session tickets lack random ticket_age_add in crypto/tls
Published 2022-08-09 · Modified
3.1EPSS 0.011
CVE-2026-27139
FileInfo can escape from a Root in os
Published 2026-03-06 · Analyzed
2.5EPSS 0.001
← Prev5 / 5