Overview
- Go standard library
- mime
- mime
02 Jun 2026
Published
01 Oct 2026
Updated
CVSS
Pending
EPSS
0.56%
KEV
Description
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- os
- os
06 Mar 2026
Published
09 Mar 2026
Updated
CVSS
Pending
EPSS
0.11%
KEV
Description
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Apache Software Foundation
- Apache Log4j Core
- org.apache.logging.log4j:log4j-core
18 Dec 2025
Published
10 Apr 2026
Updated
CVSS
Pending
EPSS
0.77%
KEV
Description
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true.
This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:
* The attacker is able to intercept or redirect network traffic between the client and the log receiver.
* The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).
Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.
As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
08 Apr 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.62%
KEV
Description
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go toolchain
- cmd/go
- cmd/go
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.16%
KEV
Description
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- FasterXML
- jackson-databind
23 Jun 2026
Published
24 Jun 2026
Updated
CVSS v4.0
MEDIUM (6.3)
EPSS
0.62%
KEV
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode (ObjectMapper.readTree()) and writes out same (or modifided) node using JsonNode.toString(). This can consume significant amount of resources with concurrent relatively small requests (1000 nested arrays is 2kB). This vulnerability is fixed in 2.14.0.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- html/template
- html/template
06 Mar 2026
Published
16 Mar 2026
Updated
CVSS
Pending
EPSS
0.33%
KEV
Description
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- archive/tar
- archive/tar
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.44%
KEV
Description
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net/textproto
- net/textproto
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.56%
KEV
Description
The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- crypto/tls
- crypto/tls
08 Jul 2026
Published
08 Jul 2026
Updated
CVSS
Pending
EPSS
0.38%
KEV
Description
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Statistics
- 1 Post
Last activity: 3 hours ago