Skip to main content

Vendor archive

golang CVEs

Beta · best-effort

222 CVEs tagged to vendor golang30 Critical, 122 High, 67 Medium, 3 Low, 0 Unrated.

CVE-2021-23772

Published Dec 24, 2021

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadForm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38297

Published Oct 18, 2021

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33198

Published Aug 2, 2021

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33197

Published Aug 2, 2021

In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary heade…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33196

Published Aug 2, 2021

In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2666

Published Jul 9, 2021

golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31525

Published May 27, 2021

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Tran…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33194

Published May 26, 2021

golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27919

Published Mar 11, 2021

archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27918

Published Mar 11, 2021

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3121

Published Jan 11, 2021

An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28852

Published Jan 2, 2021

In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28851

Published Jan 2, 2021

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an H…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29652

Published Dec 17, 2020

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29511

Published Dec 14, 2020

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 151-175 of 222 CVEsPage 7 of 9