-Infinity
0

Golang GoRoot escape via symlink plus trailing slash in os

Risk 74
Severity
7.8
First published (updated )

go crypto/x509 (Certificate.VerifyHostname / VerifyHostname via Verify)(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject A…

Risk 33
Severity
7
First published (updated )

Microsoft azl3 golang 1.26.3-1Quadratic complexity in WordDecoder.DecodeHeader in mime

Risk 46
Severity
7.5
First published (updated )

oss-secGo 1.26.3 and Go 1.25.10 aleased with 11 security fixes

go net/http ReverseProxyReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used w…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go go tool packThe "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good…

Risk 19
Severity
4
First published (updated )

go GoWhen using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-fr…

Risk 33
Severity
7
First published (updated )

Golang GoBypass of meta content URL escaping causes XSS in html/template

Risk 40
Severity
6.1
First published (updated )

Golang GoInvoking "go tool pack" does not sanitize output paths in cmd/go

Risk 35
Severity
5.9
First published (updated )

Golang GoInvoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

Risk 38
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Golang GoReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

Risk 28
Severity
5.3
First published (updated )

Golang GoQuadratic string concatenation in consumePhrase in net/mail

Risk 46
Severity
7.5
First published (updated )

go Lego (ACME client)Path Traversal

Risk 33
Severity
7
First published (updated )

go crypto/x509During chain building, the amount of work that is done is not correctly limited when a large number …

Risk 33
Severity
7
First published (updated )

go Go crypto/x509When verifying a certificate chain containing excluded DNS constraints, these constraints are not co…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Golang GoInefficient policy validation in crypto/x509

Risk 46
Severity
7.5
First published (updated )

Golang GoUnexpected work during chain building in crypto/x509

Risk 46
Severity
7.5
First published (updated )

Golang GoMissing bound checks can lead to memory corruption in safe Go in cmd/compile

Risk 91
Severity
9.8
First published (updated )

Golang GoUnauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

Risk 46
Severity
7.5
First published (updated )

Golang GoCode execution vulnerability in SWIG code generation in cmd/go

Risk 79
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go crypto/x509Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

Risk 70
Severity
8.8
First published (updated )

Golang GoTOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

Risk 60
Severity
6.4
First published (updated )

go net/urlurl.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Risk 33
Severity
7
First published (updated )

Golang GoIncorrect parsing of IPv6 host literals in net/url

Risk 46
Severity
7.5
First published (updated )

go Go MCP SDKThe Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message pars…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go crypto/tls (Go standard library)During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs field…

Risk 19
Severity
4
First published (updated )

golang.org/x/net/htmlInfinite parsing loop in golang.org/x/net

Risk 27
Severity
5.3
First published (updated )

golang.org/x/net/htmlQuadratic parsing complexity in golang.org/x/net/html

Risk 27
Severity
5.3
First published (updated )

Golang GoHandshake messages may be processed at the incorrect encryption level in crypto/tls

Risk 29
Severity
5.3
First published (updated )

oss-secCVE-2025-68121: gssion and Incomplete Fix for Go TLS Session sumption

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203