Golang
Golang GO: vulnerabilidades y CVE
Golang GO tiene 181 vulnerabilidades publicadas, 47 de ellas en los últimos 12 meses. 18 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE181
Últimos 12 meses47
Críticas18
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2020-0601 | Alta (8.1) | 89% | ⚠ Explotación activa | 14 ene 2020 | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58507 | Media (5.3) | 0.38% | — | 13 ago 2026 | Private Repository Existence Disclosure via go-get Meta Endpoint |
| CVE-2026-42505 | Media (5.3) | 0.38% | — | 8 jul 2026 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. |
| CVE-2026-39822 | Alta (7.8) | 0.23% | — | 8 jul 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example,… |
| CVE-2023-54365 | Alta (8.7) | 0.77% | — | 23 jun 2026 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the… |
| CVE-2026-42501 | Alta (7.5) | 0.29% | — | 7 may 2026 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or… |
| CVE-2026-42499 | Alta (7.5) | 0.80% | — | 7 may 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. |
| CVE-2026-39836 | Alta (7.5) | 0.62% | — | 7 may 2026 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). |
| CVE-2026-39826 | Media (6.1) | 0.39% | — | 7 may 2026 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into… |
| CVE-2026-39825 | Media (5.3) | 0.41% | — | 7 may 2026 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded… |
| CVE-2026-39823 | Media (6.1) | 0.33% | — | 7 may 2026 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content>… |
| CVE-2026-39820 | Alta (7.5) | 0.87% | — | 7 may 2026 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. |
| CVE-2026-39819 | Media (5.3) | 0.15% | — | 7 may 2026 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names,… |
| CVE-2026-39817 | Media (5.9) | 0.16% | — | 7 may 2026 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write… |
| CVE-2026-33814 | Alta (7.5) | 0.78% | — | 7 may 2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. |
| CVE-2026-33811 | Alta (7.5) | 0.81% | — | 7 may 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. |
| CVE-2026-33810 | Alta (8.2) | 0.34% | — | 8 abr 2026 | When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of… |
| CVE-2026-32289 | Media (6.1) | 0.33% | — | 8 abr 2026 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals… |
| CVE-2026-32288 | Media (5.5) | 0.18% | — | 8 abr 2026 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format. |
| CVE-2026-32283 | Alta (7.5) | 0.62% | — | 8 abr 2026 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.… |
| CVE-2026-32282 | Media (6.4) | 0.29% | — | 8 abr 2026 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat… |
| CVE-2026-32281 | Alta (7.5) | 0.36% | — | 8 abr 2026 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects… |
| CVE-2026-32280 | Alta (7.5) | 0.61% | — | 8 abr 2026 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This… |
| CVE-2026-27144 | Alta (7.1) | 0.18% | — | 8 abr 2026 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially… |
| CVE-2026-27143 | Crítica (9.8) | 0.66% | — | 8 abr 2026 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption. |
| CVE-2026-27140 | Alta (8.8) | 0.81% | — | 8 abr 2026 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. |
| CVE-2026-27142 | Media (6.1) | 0.33% | — | 6 mar 2026 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added,… |
| CVE-2026-27139 | Baja (2.5) | 0.11% | — | 6 mar 2026 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is… |
| CVE-2026-27138 | Media (5.9) | 0.32% | — | 6 mar 2026 | Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying… |
| CVE-2026-27137 | Alta (7.5) | 0.66% | — | 6 mar 2026 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly… |
| CVE-2026-25679 | Alta (7.5) | 0.80% | — | 6 mar 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.