24h | 7d | 30d

Overview

  • Go standard library
  • net/mail
  • net/mail

29 Oct 2025
Published
09 Dec 2025
Updated

CVSS
Pending
EPSS
0.65%

KEV

Description

The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • FasterXML
  • jackson-databind

23 Jun 2026
Published
24 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
1.00%

KEV

Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go toolchain
  • cmd/cgo
  • cmd/cgo

05 Feb 2026
Published
10 Sep 2026
Updated

CVSS
Pending
EPSS
0.49%

KEV

Description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go standard library
  • os
  • os

08 Jul 2026
Published
08 Jul 2026
Updated

CVSS
Pending
EPSS
0.23%

KEV

Description

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go standard library
  • html/template
  • html/template

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.33%

KEV

Description

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go standard library
  • net/mail
  • net/mail

07 May 2026
Published
18 Sep 2026
Updated

CVSS
Pending
EPSS
0.87%

KEV

Description

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Apache Software Foundation
  • Apache Log4j Core
  • org.apache.logging.log4j:log4j-core

10 Apr 2026
Published
10 Apr 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
1.19%

KEV

Description

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records. * Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger. Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go standard library
  • internal/syscall/unix
  • internal/syscall/unix

08 Apr 2026
Published
13 Apr 2026
Updated

CVSS
Pending
EPSS
0.29%

KEV

Description

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go standard library
  • crypto/x509
  • crypto/x509

29 Oct 2025
Published
20 Nov 2025
Updated

CVSS
Pending
EPSS
0.41%

KEV

Description

Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2025-48924 CVE-2025-52999 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723 CVE-2025-61724 CVE-2025-61725 CVE-2025-61726 CVE-2025-61727 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-61731 CVE-2025-61732
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Go toolchain
  • cmd/compile
  • cmd/compile

08 Apr 2026
Published
13 Apr 2026
Updated

CVSS
Pending
EPSS
0.18%

KEV

Description

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 2h ago
Showing 171 to 180 of 185 CVEs