Skip to main content

Vendor archive

golang CVEs

Beta · best-effort

222 CVEs tagged to vendor golang30 Critical, 122 High, 67 Medium, 3 Low, 0 Unrated.

CVE-2021-43565

Published Sep 6, 2022

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32189

Published Aug 10, 2022

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32148

Published Aug 10, 2022

Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30635

Published Aug 10, 2022

Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30633

Published Aug 10, 2022

Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30632

Published Aug 10, 2022

Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30631

Published Aug 10, 2022

Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a larg…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30630

Published Aug 10, 2022

Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of pat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30629

Published Aug 10, 2022

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive con…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30580

Published Aug 10, 2022

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29804

Published Aug 10, 2022

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1962

Published Aug 10, 2022

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or de…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1705

Published Aug 10, 2022

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27536

Published Apr 20, 2022

Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39293

Published Jan 24, 2022

In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 222 CVEsPage 6 of 9