Golang
Golang NET: vulnerabilidades y CVE
Golang NET tiene 15 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-67201 | Alta (7.7) | 0.53% | — | 29 jul 2026 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between… |
| CVE-2025-68049 | Media (6.3) | 0.24% | — | 15 jun 2026 | Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. |
| CVE-2026-42506 | Media (6.1) | 0.33% | — | 22 may 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. |
| CVE-2026-42502 | Media (6.1) | 0.22% | — | 22 may 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. |
| CVE-2026-39821 | Crítica (9.6) | 0.69% | — | 22 may 2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an… |
| CVE-2026-27136 | Media (6.1) | 0.22% | — | 22 may 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. |
| CVE-2026-25681 | Media (6.1) | 0.22% | — | 22 may 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. |
| CVE-2026-25680 | Media (6.5) | 0.46% | — | 22 may 2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. |
| CVE-2024-4436 | Alta (7.5) | 0.77% | — | 8 may 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using… |
| CVE-2018-17848 | Alta (7.5) | 2.2% | — | 1 oct 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from… |
| CVE-2018-17847 | Alta (7.5) | 2.4% | — | 1 oct 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from… |
| CVE-2018-17846 | Alta (7.5) | 2.5% | — | 1 oct 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not… |
| CVE-2018-17143 | Alta (7.5) | 2.8% | — | 17 sept 2018 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call. |
| CVE-2018-17142 | Alta (7.5) | 2.4% | — | 17 sept 2018 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call. |
| CVE-2018-17075 | Alta (7.5) | 2.8% | — | 16 sept 2018 | The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.