Go 1.x — End of Life
Active Critical risk17 releases in this series568 CVEs
Go 1.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 1.26 | Feb 10, 2026 | — | No | 1.26.5 | Active | |
| 1.25 | Aug 12, 2025 | — | No | 1.25.12 | Active | |
| 1.24 | Feb 11, 2025 | — | Feb 10, 2026 | 1.24.13 | EOL | |
| 1.23 | Aug 13, 2024 | — | Aug 12, 2025 | 1.23.12 | EOL | |
| 1.22 | Feb 6, 2024 | — | Feb 11, 2025 | 1.22.12 | EOL | |
| 1.21 | Aug 8, 2023 | — | Aug 13, 2024 | 1.21.13 | EOL | |
| 1.20 | Feb 1, 2023 | — | Feb 6, 2024 | 1.20.14 | EOL | |
| 1.19 | Aug 2, 2022 | — | Sep 6, 2023 | 1.19.13 | EOL | |
| 1.18 | Mar 15, 2022 | — | Feb 1, 2023 | 1.18.10 | EOL | |
| 1.17 | Aug 16, 2021 | — | Aug 2, 2022 | 1.17.13 | EOL | |
| 1.16 | Feb 16, 2021 | — | Mar 15, 2022 | 1.16.15 | EOL | |
| 1.15 | Aug 11, 2020 | — | Aug 16, 2021 | 1.15.15 | EOL | |
| 1.14 | Feb 25, 2020 | — | Feb 16, 2021 | 1.14.15 | EOL | |
| 1.13 | Sep 3, 2019 | — | Aug 11, 2020 | 1.13.15 | EOL | |
| 1.12 | Feb 25, 2019 | — | Feb 25, 2020 | 1.12.17 | EOL | |
| 1.11 | Aug 24, 2018 | — | Sep 3, 2019 | 1.11.13 | EOL | |
| 1.10 | Feb 16, 2018 | — | Feb 25, 2019 | 1.10.8 | EOL |
CVEs affecting Go 1.x (568)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.19 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.24 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.23 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.16 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.15 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.22 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.21 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.20 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.12 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.11 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.10 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.26 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.25 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.17 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.13 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.14 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.25% | — | 1.18 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.10 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.16 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.15 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.22 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.21 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.20 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.19 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.18 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.14 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.13 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.12 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.11 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.26 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.17 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.25 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.24 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2026-39822 | HIGH | 7.8 | 0.23% | — | 1.23 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina… | Jul 8, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.14 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.13 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.12 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.11 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.10 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.21 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.18 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.19 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.20 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.15 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.16 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2023-54365 | HIGH | 7.5 | 0.57% | — | 1.17 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri… | Jun 23, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.22 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.26 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.10 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.11 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.12 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.13 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.14 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.15 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.16 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.17 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.18 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.19 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.20 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.21 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.23 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.24 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42501 | HIGH | 7.5 | 0.23% | — | 1.25 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa… | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.25 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.26 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.10 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.11 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.12 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.13 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.14 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.15 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.16 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.17 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.18 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.19 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.20 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.21 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.22 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.23 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-42499 | HIGH | 7.5 | 0.80% | — | 1.24 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.23 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.26 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.10 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.11 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.12 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.13 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.14 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.15 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.16 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.17 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.18 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.19 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.20 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.21 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.25 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.22 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39836 | HIGH | 7.5 | 0.59% | — | 1.24 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.20 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.18 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.25 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.24 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.23 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.22 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.21 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.19 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.17 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.16 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.15 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.14 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.13 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.12 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.11 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.10 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.37% | — | 1.26 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.13 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.12 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.11 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.10 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.14 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.26 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.15 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.16 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.17 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.18 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.19 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.20 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.21 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.22 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.23 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.24 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.39% | — | 1.25 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.22 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.26 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.10 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.11 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.12 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.13 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.14 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.15 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.16 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.17 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.18 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.19 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.20 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.21 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.23 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.24 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.31% | — | 1.25 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.25 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.26 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.10 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.11 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.12 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.13 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.14 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.15 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.17 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.18 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.19 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.20 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.21 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.22 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.16 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.23 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39820 | HIGH | 7.5 | 0.78% | — | 1.24 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.26 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.10 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.11 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.12 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.13 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.14 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.15 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.16 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.17 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.18 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.19 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.20 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.21 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.22 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.23 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.24 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.18% | — | 1.25 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.25 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.26 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.10 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.11 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.12 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.13 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.14 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.15 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.16 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.17 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.18 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.19 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.20 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.21 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.22 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.23 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.17% | — | 1.24 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.17 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.26 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.10 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.11 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.12 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.13 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.14 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.15 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.16 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.18 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.19 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.20 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.21 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.22 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.23 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.24 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33814 | HIGH | 7.5 | 0.78% | — | 1.25 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.26 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.10 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.11 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.12 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.13 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.14 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.15 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.16 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.17 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.18 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.19 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.20 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.21 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.22 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.23 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.24 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33811 | HIGH | 7.5 | 0.81% | — | 1.25 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a… | May 7, 2026 |
| CVE-2026-33810 | HIGH | 8.2 | 0.34% | — | 1.26 | When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.10 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.26 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.16 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.15 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.24 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.23 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.22 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.21 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.20 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.11 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.19 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.25 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.18 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.17 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.14 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.13 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.29% | — | 1.12 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.24 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.26 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.25 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.17 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.16 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.15 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.23 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.22 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.21 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.20 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.19 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.18 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.14 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.13 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.12 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.11 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.29% | — | 1.10 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.20 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.21 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.22 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.23 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.24 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.15 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.16 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.17 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.25 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.26 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.10 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.11 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.12 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.13 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.14 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.18 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32283 | HIGH | 7.5 | 0.62% | — | 1.19 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.23 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.25 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.17 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.16 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.15 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.24 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.18 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.22 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.26 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.10 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.11 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.12 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.13 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.14 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.21 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.20 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.29% | — | 1.19 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.14 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.18 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.19 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.26 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.20 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.21 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.22 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.23 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.10 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.24 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.15 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.16 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.17 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.25 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.11 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.12 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32281 | HIGH | 7.5 | 0.36% | — | 1.13 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.19 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.25 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.17 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.16 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.15 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.24 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.23 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.22 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.21 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.20 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.18 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.14 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.13 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.12 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.11 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.10 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-32280 | HIGH | 7.5 | 0.61% | — | 1.26 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.11 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.12 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.13 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.14 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.18 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.19 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.20 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.21 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.22 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.23 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.24 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.15 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.26 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.16 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.25 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.10 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27144 | HIGH | 7.1 | 0.26% | — | 1.17 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.19 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.25 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.17 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.16 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.15 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.24 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.23 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.22 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.21 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.20 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.18 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.14 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.13 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.12 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.26 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.10 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.54% | — | 1.11 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp… | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.14 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.13 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.12 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.25 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.17 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.16 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.15 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.24 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.23 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.22 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.21 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.20 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.19 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.18 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.11 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.26 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27140 | HIGH | 8.8 | 0.66% | — | 1.10 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at … | Apr 8, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.10 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.25 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.17 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.16 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.15 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.24 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.23 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.22 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.21 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.20 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.19 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.18 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.14 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.13 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.12 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.11 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.33% | — | 1.26 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.24 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.23 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.15 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.25 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.17 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.16 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.26 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.10 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.11 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.12 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.13 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.14 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.18 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.19 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.20 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.21 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27139 | LOW | 2.5 | 0.20% | — | 1.22 | On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou… | Mar 6, 2026 |
| CVE-2026-27138 | MEDIUM | 5.9 | 0.35% | — | 1.26 | Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the … | Mar 6, 2026 |
| CVE-2026-27137 | HIGH | 7.5 | 0.61% | — | 1.26 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar… | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.22 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.10 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.11 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.12 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.13 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.14 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.18 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.19 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.26 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.25 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.17 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.16 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.15 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.24 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.23 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.21 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2026-25679 | HIGH | 7.5 | 0.73% | — | 1.20 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.19 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.10 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.20 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.21 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.22 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.23 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.24 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.15 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.16 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.17 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.18 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.25 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.26 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.11 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.14 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.12 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-68121 | CRITICAL | 10.0 | 0.77% | — | 1.13 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th… | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.25 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.17 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.16 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.15 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.24 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.23 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.10 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.22 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.11 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.12 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.13 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.14 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.18 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.19 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.20 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-61732 | HIGH | 8.6 | 0.47% | — | 1.21 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.15 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.16 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.17 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.13 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.14 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.18 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.19 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.11 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.20 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.21 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.24 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.10 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.12 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.22 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-22873 | LOW | 3.8 | 0.24% | — | 1.23 | It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp… | Feb 4, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.23 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.22 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.24 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.15 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.16 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.17 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.25 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.10 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.11 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.12 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.13 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.14 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.18 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.19 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.20 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-68119 | HIGH | 7.0 | 0.34% | — | 1.21 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.23 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.19 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.18 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.14 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.13 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.12 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.11 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.10 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.25 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.17 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.16 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.15 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.24 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.22 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.21 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61731 | HIGH | 7.8 | 0.53% | — | 1.20 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.12 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.16 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.15 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.24 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.23 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.22 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.21 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.13 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.14 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.18 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.20 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.19 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.25 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.10 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.11 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61730 | MEDIUM | 5.3 | 0.28% | — | 1.17 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.15 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.11 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.12 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.13 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.14 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.18 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.19 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.20 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.21 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.22 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.23 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.24 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.10 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.16 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.17 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61728 | MEDIUM | 6.5 | 0.64% | — | 1.25 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.16 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.15 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.24 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.23 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.22 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.21 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.20 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.19 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.18 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.14 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.13 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.12 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.11 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.10 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.25 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
| CVE-2025-61726 | HIGH | 7.5 | 1.94% | — | 1.17 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p… | Jan 28, 2026 |
Frequently asked questions
Is Go 1 end of life?
Partially. Some Go 1.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Go 1?
There are 568 CVEs tracked for Go 1.x, including 34 critical severity issues. See the full list above with CVSS and EPSS scores.
What is the latest Go 1 version?
The latest Go 1.x patch release is 1.26.5, released on July 7, 2026. Always run the latest patch to benefit from all security fixes.
When was Go 1 first released?
Go 1.0 was initially released on February 10, 2026. See the full version timeline in the table above.
Is it safe to run Go 1 in production?
Go 1 is still supported and safe for production use. Ensure you are running the latest patch version (1.26.5) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
