Vulnerabilities > Golang > GO > 1.19.10

DATE CVE VULNERABILITY TITLE RISK
2023-09-08 CVE-2023-39319 Cross-site Scripting vulnerability in Golang GO
The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts.
network
low complexity
golang CWE-79
6.1
2023-08-02 CVE-2023-29409 Resource Exhaustion vulnerability in Golang GO
Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures.
network
low complexity
golang CWE-400
5.3
2023-07-11 CVE-2023-29406 Interpretation Conflict vulnerability in Golang GO
The HTTP/1 client does not fully validate the contents of the Host header.
network
low complexity
golang CWE-436
6.5