« Volver al listado

Golang

Golang GO: vulnerabilidades y CVE

Golang GO tiene 181 vulnerabilidades publicadas, 47 de ellas en los últimos 12 meses. 18 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE181
Últimos 12 meses47
Críticas18
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2020-0601Alta (8.1)89%⚠ Explotación activa14 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-58507Media (5.3)0.38%—13 ago 2026
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-42505Media (5.3)0.38%—8 jul 2026
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
CVE-2026-39822Alta (7.8)0.23%—8 jul 2026
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example,…
CVE-2023-54365Alta (8.7)0.77%—23 jun 2026
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the…
CVE-2026-42501Alta (7.5)0.29%—7 may 2026
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or…
CVE-2026-42499Alta (7.5)0.80%—7 may 2026
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-39836Alta (7.5)0.62%—7 may 2026
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
CVE-2026-39826Media (6.1)0.39%—7 may 2026
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into…
CVE-2026-39825Media (5.3)0.41%—7 may 2026
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded…
CVE-2026-39823Media (6.1)0.33%—7 may 2026
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content>…
CVE-2026-39820Alta (7.5)0.87%—7 may 2026
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-39819Media (5.3)0.15%—7 may 2026
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names,…
CVE-2026-39817Media (5.9)0.16%—7 may 2026
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write…
CVE-2026-33814Alta (7.5)0.78%—7 may 2026
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
CVE-2026-33811Alta (7.5)0.81%—7 may 2026
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVE-2026-33810Alta (8.2)0.34%—8 abr 2026
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of…
CVE-2026-32289Media (6.1)0.33%—8 abr 2026
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals…
CVE-2026-32288Media (5.5)0.18%—8 abr 2026
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVE-2026-32283Alta (7.5)0.62%—8 abr 2026
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.…
CVE-2026-32282Media (6.4)0.29%—8 abr 2026
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat…
CVE-2026-32281Alta (7.5)0.36%—8 abr 2026
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects…
CVE-2026-32280Alta (7.5)0.61%—8 abr 2026
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This…
CVE-2026-27144Alta (7.1)0.18%—8 abr 2026
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially…
CVE-2026-27143Crítica (9.8)0.66%—8 abr 2026
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
CVE-2026-27140Alta (8.8)0.81%—8 abr 2026
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVE-2026-27142Media (6.1)0.33%—6 mar 2026
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added,…
CVE-2026-27139Baja (2.5)0.11%—6 mar 2026
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is…
CVE-2026-27138Media (5.9)0.32%—6 mar 2026
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying…
CVE-2026-27137Alta (7.5)0.66%—6 mar 2026
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly…
CVE-2026-25679Alta (7.5)0.80%—6 mar 2026
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1036.001 Invalid Code Signature1
  2. T1190 Exploit Public-Facing Application1
  3. T1203 Exploitation for Client Execution1
  4. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Golang