Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Golang GO | 28/2/2023 | 17/6/2026 | A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the… | |
| Modificada | Alta (7.5) | 1.8% | — | Golang H2C | 13/1/2023 | 17/6/2026 | A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent… | |
| Modificada | Crítica (9.1) | 0.85% | — | Digitalocean Golang-nanoauth | 27/12/2022 | 17/6/2026 | Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token. | |
| Modificada | Alta (7.5) | 1.4% | — | Golang Text | 26/12/2022 | 17/6/2026 | golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack. | |
| Modificada | Media (6.1) | 0.56% | — | Studygolang | 21/12/2022 | 17/6/2026 | A vulnerability classified as problematic was found in studygolang. This vulnerability affects the function Search of the file http/controller/search.go. The manipulation of the argument q leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (6.1) | 0.40% | — | Studygolang | 21/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is… | |
| Modificada | Media (5.3) | 5.8% | 💥 PoC | Golang GOGolang Http2Fedoraproject Fedora | 8/12/2022 | 17/6/2026 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB… | |
| Modificada | Alta (7.5) | 1.3% | — | Golang GO | 7/12/2022 | 17/6/2026 | On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS("C:/tmp").Open("COM1") opens the COM1 device. Both… | |
| Modificada | Alta (7.5) | 0.84% | — | Golang GO | 2/11/2022 | 17/6/2026 | Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for… | |
| Modificada | Alta (7.5) | 1.4% | — | Golang GO | 14/10/2022 | 17/6/2026 | Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts… | |
| Modificada | Alta (7.5) | 1.5% | — | Golang Text | 14/10/2022 | 17/6/2026 | An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse. | |
| Modificada | Alta (7.5) | 1.2% | — | Golang GO | 14/10/2022 | 17/6/2026 | Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the… | |
| Modificada | Alta (7.5) | 1.7% | — | Golang GO | 14/10/2022 | 17/6/2026 | Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB. | |
| Modificada | Alta (7.8) | 0.61% | — | Snyk CLISnyk Golang CLI | 3/10/2022 | 17/6/2026 | Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json… | |
| Modificada | Alta (7.5) | 2.2% | — | Golang GO | 13/9/2022 | 17/6/2026 | JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result. | |
| Modificada | Alta (7.5) | 3.3% | — | Golang GOFedoraproject Fedora | 6/9/2022 | 17/6/2026 | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. | |
| Modificada | Alta (7.5) | 1.1% | — | Golang SSH | 6/9/2022 | 17/6/2026 | The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. | |
| Modificada | Alta (7.5) | 2.6% | — | Golang GO | 10/8/2022 | 17/6/2026 | A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. | |
| Modificada | Media (6.5) | 1.4% | — | Golang GO | 10/8/2022 | 17/6/2026 | Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header. | |
| Modificada | Alta (7.5) | 1.8% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures. | |
| Modificada | Alta (7.5) | 2.1% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag. | |
| Modificada | Alta (7.5) | 2.1% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators. | |
| Modificada | Alta (7.5) | 2.1% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files. | |
| Modificada | Alta (7.5) | 2.1% | — | Golang GO | 10/8/2022 | 17/6/2026 | Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators. | |
| Modificada | Baja (3.1) | 1.1% | — | Golang GO | 10/8/2022 | 17/6/2026 | Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption. |