Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.36% | — | Golang PlaygroundAI | 25/9/2026 | 29/9/2026 | A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Nginx IgnitionAIGolang X TextAI | 21/9/2026 | 24/9/2026 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape… | |
| Analizada | Alta (7.5) | 0.43% | — | Golang Crypto | 2/9/2026 | 4/9/2026 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet… | |
| Analizada | Alta (7.5) | 0.50% | — | Golang Crypto | 2/9/2026 | 4/9/2026 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openshift Oauth-serverAIGolang.org X TextAI | 1/9/2026 | 1/9/2026 | A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the… | |
| Aplazada | Alta (8.7) | 0.51% | — | Ech0AIGolang X/textAI | 25/8/2026 | 31/8/2026 | Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLanguage. The CVE-2022-32149 mitigation in… | |
| Pendiente de análisis | Alta (7.5) | 0.41% | — | Golang X ImageAI | 14/8/2026 | 3/9/2026 | VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. | |
| Aplazada | Media (5.3) | 0.38% | — | Golang GOAI | 13/8/2026 | 26/8/2026 | Private Repository Existence Disclosure via go-get Meta Endpoint | |
| Aplazada | Media (5.9) | 0.40% | — | GorestAIGolang GINAI | 4/8/2026 | 10/9/2026 | GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from… | |
| Aplazada | Alta (7.7) | 0.53% | — | Golang NETAIGolang UrllibAI | 29/7/2026 | 30/7/2026 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that… | |
| Analizada | Media (5.3) | 0.38% | — | Golang GO | 8/7/2026 | 16/9/2026 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. | |
| Analizada | Alta (7.8) | 0.23% | — | Golang GO | 8/7/2026 | 17/9/2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. | |
| Analizada | Alta (7.5) | 0.61% | — | Golang Tiff | 26/6/2026 | 1/7/2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. | |
| Analizada | Alta (8.7) | 0.77% | — | TraefikGolang GORedhat Openshift AI | 23/6/2026 | 26/9/2026 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust… | |
| Aplazada | Media (6.3) | 0.24% | — | Golang NETAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Golang Net/textprotoAI | 2/6/2026 | 22/7/2026 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | |
| Pendiente de análisis | Media (6.5) | 0.59% | — | Golang X509AI | 2/6/2026 | 18/9/2026 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries… | |
| Analizada | Media (6.1) | 0.33% | — | Golang NET | 22/5/2026 | 23/7/2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| Analizada | Media (6.1) | 0.22% | — | Golang NET | 22/5/2026 | 23/7/2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| Modificada | Crítica (9.6) | 0.69% | — | Golang NET | 22/5/2026 | 17/9/2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example,… | |
| Analizada | Media (6.1) | 0.22% | — | Golang NET | 22/5/2026 | 23/7/2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| Analizada | Media (6.1) | 0.22% | — | Golang NET | 22/5/2026 | 23/7/2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| Analizada | Media (6.5) | 0.46% | — | Golang NET | 22/5/2026 | 23/7/2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. | |
| Analizada | Media (5.3) | 0.52% | — | Golang Crypto | 22/5/2026 | 23/7/2026 | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used. | |
| Analizada | Alta (7.5) | 0.62% | — | Golang Crypto | 22/5/2026 | 23/7/2026 | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs. |