Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

266 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.63%—Golang GO10/8/202217/6/2026
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
ModificadaAlta (7.5)2.3%—Golang GO10/8/202217/6/2026
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
ModificadaAlta (7.5)2.4%—Golang GOFedoraproject FedoraNetapp Cloud Insights Telegraf10/8/202217/6/2026
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
ModificadaMedia (5.5)0.92%—Golang GO10/8/202217/6/2026
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.
ModificadaMedia (6.5)1.4%—Golang GO10/8/202217/6/2026
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
ModificadaAlta (7.5)2.3%—Golang GONetapp Cloud Insights Telegraf Agent15/7/202217/6/2026
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.
ModificadaMedia (5.3)3.0%—Golang GOFedoraproject FedoraNetapp Beegfs CSI Driver23/6/202217/6/2026
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
ModificadaAlta (7.5)4.2%—Golang GOFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora20/4/202217/6/2026
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
ModificadaAlta (7.5)1.5%—Golang GO20/4/202217/6/2026
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.
ModificadaAlta (7.5)10.0%💥 PoCGolang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator20/4/202217/6/2026
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
ModificadaAlta (7.5)3.9%—Golang SSHFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Advanced Cluster Management FOR Kubernetes18/3/202217/6/2026
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
ModificadaAlta (7.5)3.2%—Golang GONetapp Astra TridentDebian Linux5/3/202217/6/2026
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
ModificadaAlta (7.5)6.0%—Prometheus Client GolangFedoraproject FedoraFedoraproject Extra Packages FOR Enterprise LinuxRDO Project RDO15/2/202217/6/2026
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory…
ModificadaCrítica (9.1)3.1%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
ModificadaAlta (7.5)2.7%💥 PoCGolang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+111/2/202217/6/2026
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
ModificadaAlta (7.5)2.8%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
ModificadaAlta (7.5)6.9%—Golang GONetapp Cloud Insights Telegraf24/1/202217/6/2026
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.
ModificadaMedia (4.8)1.9%—Golang GODebian Linux1/1/202217/6/2026
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
ModificadaAlta (7.5)4.0%—Golang GODebian LinuxNetapp Cloud Insights Telegraf1/1/202217/6/2026
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
ModificadaAlta (7.5)3.3%—Golang GOFedoraproject FedoraOracle Timesten In-memory Database8/11/202117/6/2026
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
ModificadaAlta (7.5)4.7%—Golang GOFedoraproject FedoraDebian Linux8/11/202117/6/2026
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
ModificadaCrítica (9.8)11%💥 PoCGolang GOFedoraproject Fedora18/10/202117/6/2026
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
ModificadaMedia (6.5)0.43%—In-toto-golang21/9/202117/6/2026
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to create attestations that may bypass DISALLOW rules in the same layout. An…
ModificadaMedia (5.9)3.1%—Golang GOFedoraproject FedoraDebian LinuxOracle Timesten In-memory Database+18/8/202117/6/2026
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
ModificadaAlta (7.5)3.7%—Golang GOOracle Timesten In-memory DatabaseFedoraproject Fedora7/8/202117/6/2026
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
Orbitaley — Vulnerabilidades