Overview
- Go standard library
- database/sql
- database/sql
07 Aug 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.37%
KEV
Description
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net/http/internal
- net/http/internal
08 Apr 2025
Published
12 May 2026
Updated
CVSS
Pending
EPSS
0.81%
KEV
Description
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/internal/nistec
- crypto/internal/nistec
06 Feb 2025
Published
21 Feb 2025
Updated
CVSS
Pending
EPSS
0.29%
KEV
Description
Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go toolchain
- cmd/go
- cmd/go
28 Jan 2026
Published
10 Sep 2026
Updated
CVSS
Pending
EPSS
0.62%
KEV
Description
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
03 Dec 2025
Published
03 Dec 2025
Updated
CVSS
Pending
EPSS
0.28%
KEV
Description
An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- encoding/asn1
- encoding/asn1
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.56%
KEV
Description
Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/tls
- crypto/tls
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.47%
KEV
Description
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Apache Software Foundation
- Apache Commons Lang
- commons-lang:commons-lang
11 Jul 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
2.27%
KEV
Description
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net
- net
07 May 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.81%
KEV
Description
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
02 Dec 2025
Published
03 Dec 2025
Updated
CVSS
Pending
EPSS
0.46%
KEV
Description
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.
Statistics
- 1 Post
Last activity: 3 hours ago