Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-xghw-p77p-3r7x
  • Go/github.com/hyperledger/fabric-ca
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter yesterday
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-2j9v-p4xj-cjw2
  • Go/github.com/lima-vm/lima/v2
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket yesterday
  • Fix available
  • Severity - 8.2 (High)
GO-2026-6222
  • Go/golang.org/x/image
Excessive memory allocation during VP8L decoding in golang.org/x/image 2 days ago
  • Fix available
GHSA-29rf-f4vv-pvq6
  • Go/github.com/authorizerdev/authorizer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts 2 days ago
  • Fix available
  • Severity - 8.7 (High)
GO-2026-5972
  • Go/stdlib
Enforce maximum recursion depth in encoding/asn1 2 days ago
  • Fix available
GO-2026-6088
  • Go/stdlib
Add recursion depth guard during decode in encoding/xml 2 days ago
  • Fix available
GO-2026-6089
  • Go/stdlib
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http 2 days ago
  • Fix available
GO-2026-6090
  • Go/stdlib
Limit handshake messages we are willing to accept post-handshake in crypto/tls 2 days ago
  • Fix available
GO-2026-6091
  • Go/stdlib
Fix Javascript regexp context tracking in html/template 2 days ago
  • Fix available
GO-2026-6179
  • Go/golang.org/x/mod
  • Go/toolchain
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog 2 days ago
  • Fix available
GO-2026-6180
  • Go/golang.org/x/mod
  • Go/toolchain
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb 2 days ago
  • Fix available
GO-2026-6218
  • Go/stdlib
Avoid quadratic complexity in resolvePath in net/url 2 days ago
  • Fix available
GHSA-48p8-g2fx-3wwm
  • Go/github.com/argoproj/argo-workflows
  • Go/github.com/argoproj/argo-workflows/v3
  • Go/github.com/argoproj/argo-workflows/v4
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) 3 days ago
  • Fix available
  • Severity - 8.9 (High)
GHSA-w62w-66v9-vvgv
  • Go/github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access 3 days ago
  • Fix available
  • Severity - 7.8 (High)
GHSA-88p2-jj8w-j8qg
  • Go/github.com/fleetdm/fleet/v4
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint 4 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GO-2026-5306
  • Go/github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd 4 days ago
  • No fix available