Where
-Infinity
0

Golang GoInvoking Encrypted Client Hello privacy leak in crypto/tls

Risk 30
Severity
5.3
First published (updated )

Golang GoRoot escape via symlink plus trailing slash in os

Risk 74
Severity
7.8
First published (updated )

golang.org/x/image/tiffPanic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image

Risk 43
Severity
7.5
First published (updated )

Traefik traefikTraefik - Denial of Service via HTTP/2 Request Handling

Risk 47
Severity
8.7
First published (updated )

Microsoft azl3 docker-compose 2.27.0-9Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft azl3 prometheus-adapter 0.12.0-5Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

Risk 37
Severity
6.5
First published (updated )

Microsoft azl3 sriov-network-device-plugin 3.7.0-5Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Microsoft azl3 telegraf 1.31.0-19Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Microsoft azl3 sriov-network-device-plugin 3.7.0-5Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Risk 38
Severity
6.1
First published (updated )

Microsoft azl3 prometheus-process-exporter 0.8.2-3Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

Risk 68
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/golang.org/x/crypto/sshInvoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

go/golang.org/x/crypto/sshInvoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

Risk 88
Severity
10
First published (updated )

golang/golang.org/x/crypto/sshInvoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

go/golang.org/x/crypto/ssh/agentInvoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Risk 29
Severity
5.3
First published (updated )

go/golang.org/x/crypto/ssh/knownhostsInvoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Risk 71
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/golang.org/x/crypto/sshInvoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Risk 41
Severity
6.5
First published (updated )

golang.org/x/crypto/sshInvoking infinite loop on large channel writes in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

go/golang.org/x/crypto/sshInvoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

Risk 71
Severity
9.1
First published (updated )

golang/golang.org/x/crypto/ssh/agentInvoking key constraints not enforced in golang.org/x/crypto/ssh/agent

Risk 71
Severity
9.1
First published (updated )

Microsoft azl3 kubevirt 1.7.1-2Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/golang.org/x/crypto/sshInvoking bypass of certificate restrictions in golang.org/x/crypto/ssh

Risk 85
Severity
8.8
First published (updated )

go/golang.org/x/crypto/ssh/agentInvoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

Risk 71
Severity
9.1
First published (updated )

golang/golang.org/x/crypto/sshInvoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Risk 47
Severity
7.5
First published (updated )

Golang GoBypass of meta content URL escaping causes XSS in html/template

Risk 40
Severity
6.1
First published (updated )

Golang GoQuadratic string concatentation in consumeComment in net/mail

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Golang GoCrash when handling long CNAME response in net

Risk 46
Severity
7.5
First published (updated )

Golang GoEscaper bypass leads to XSS in html/template

Risk 40
Severity
6.1
First published (updated )

Golang GoMalicious module proxy can bypass checksum database in cmd/go

Risk 72
Severity
7.5
First published (updated )

Golang GoPanic in Dial and LookupPort when handling NUL byte on Windows in net

Risk 45
Severity
7.5
First published (updated )

Golang GoInvoking "go tool pack" does not sanitize output paths in cmd/go

Risk 35
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203