Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

266 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.36%—Golang PlaygroundAI25/9/202629/9/2026
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for…
Pendiente de análisisAlta (7.5)0.42%—Nginx IgnitionAIGolang X TextAI21/9/202624/9/2026
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape…
AnalizadaAlta (7.5)0.43%—Golang Crypto2/9/20264/9/2026
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet…
AnalizadaAlta (7.5)0.50%—Golang Crypto2/9/20264/9/2026
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of…
Pendiente de análisisAlta (7.5)0.63%—Openshift Oauth-serverAIGolang.org X TextAI1/9/20261/9/2026
A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the…
AplazadaAlta (8.7)0.51%—Ech0AIGolang X/textAI25/8/202631/8/2026
Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLanguage. The CVE-2022-32149 mitigation in…
Pendiente de análisisAlta (7.5)0.41%—Golang X ImageAI14/8/20263/9/2026
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
AplazadaMedia (5.3)0.38%—Golang GOAI13/8/202626/8/2026
Private Repository Existence Disclosure via go-get Meta Endpoint
AplazadaMedia (5.9)0.40%—GorestAIGolang GINAI4/8/202610/9/2026
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from…
AplazadaAlta (7.7)0.53%—Golang NETAIGolang UrllibAI29/7/202630/7/2026
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that…
AnalizadaMedia (5.3)0.38%—Golang GO8/7/202616/9/2026
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
AnalizadaAlta (7.8)0.23%—Golang GO8/7/202617/9/2026
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
AnalizadaAlta (7.5)0.61%—Golang Tiff26/6/20261/7/2026
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
AnalizadaAlta (8.7)0.77%—TraefikGolang GORedhat Openshift AI23/6/202626/9/2026
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust…
AplazadaMedia (6.3)0.24%—Golang NETAI15/6/202617/6/2026
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
Pendiente de análisisMedia (5.3)0.41%—Golang Net/textprotoAI2/6/202622/7/2026
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
Pendiente de análisisMedia (6.5)0.59%—Golang X509AI2/6/202618/9/2026
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries…
AnalizadaMedia (6.1)0.33%—Golang NET22/5/202623/7/2026
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
AnalizadaMedia (6.1)0.22%—Golang NET22/5/202623/7/2026
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
ModificadaCrítica (9.6)0.69%—Golang NET22/5/202617/9/2026
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example,…
AnalizadaMedia (6.1)0.22%—Golang NET22/5/202623/7/2026
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
AnalizadaMedia (6.1)0.22%—Golang NET22/5/202623/7/2026
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
AnalizadaMedia (6.5)0.46%—Golang NET22/5/202623/7/2026
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
AnalizadaMedia (5.3)0.52%—Golang Crypto22/5/202623/7/2026
For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
AnalizadaAlta (7.5)0.62%—Golang Crypto22/5/202623/7/2026
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.