Overview
- Go standard library
- internal/syscall/unix
- internal/syscall/unix
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.29%
KEV
Description
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
29 Oct 2025
Published
20 Nov 2025
Updated
CVSS
Pending
EPSS
0.41%
KEV
Description
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go toolchain
- cmd/compile
- cmd/compile
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.18%
KEV
Description
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- crypto/tls
- crypto/tls
05 Feb 2026
Published
29 Apr 2026
Updated
CVSS
Pending
EPSS
0.86%
KEV
Description
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
02 Jun 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.59%
KEV
Description
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- crypto/tls
- crypto/tls
08 Apr 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.62%
KEV
Description
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- net/url
- net/url
28 Jan 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
2.33%
KEV
Description
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Apache Software Foundation
- Apache Log4j Core
- org.apache.logging.log4j:log4j-core
10 Apr 2026
Published
10 Apr 2026
Updated
CVSS v4.0
MEDIUM (6.3)
EPSS
0.50%
KEV
Description
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property, but not when configured through the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName attribute of the <Ssl> element.
Although the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.
A network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:
* An SMTP, Socket, or Syslog appender is in use.
* TLS is configured via a nested <Ssl> element.
* The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.
This issue does not affect users of the HTTP appender, which uses a separate verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName attribute that was not subject to this bug and verifies host names by default.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue.
Statistics
- 1 Post
Last activity: 2 hours ago