Vulnerabilities > Golang

DATE CVE VULNERABILITY TITLE RISK
2022-12-08 CVE-2022-41717 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests.
network
low complexity
golang fedoraproject CWE-770
5.3
2022-12-07 CVE-2022-41720 Path Traversal vulnerability in Golang GO
On Windows, restricted files can be accessed via os.DirFS and http.Dir.
network
low complexity
golang CWE-22
7.5
2022-11-02 CVE-2022-41716 Unspecified vulnerability in Golang GO
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows.
network
low complexity
golang
7.5
2022-10-14 CVE-2022-41715 Unspecified vulnerability in Golang GO
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service.
network
low complexity
golang
7.5
2022-10-14 CVE-2022-2879 Allocation of Resources Without Limits or Throttling vulnerability in Golang GO
Reader.Read does not set a limit on the maximum size of file headers.
network
low complexity
golang CWE-770
7.5
2022-10-14 CVE-2022-2880 HTTP Request Smuggling vulnerability in Golang GO
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http.
network
low complexity
golang CWE-444
7.5
2022-10-14 CVE-2022-32149 Missing Release of Resource after Effective Lifetime vulnerability in Golang Text
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
network
low complexity
golang CWE-772
7.5
2022-09-13 CVE-2022-32190 Path Traversal vulnerability in Golang GO 1.19.0
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path.
network
low complexity
golang CWE-22
7.5
2022-09-06 CVE-2021-43565 Unspecified vulnerability in Golang SSH
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.
network
low complexity
golang
7.5
2022-09-06 CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
network
low complexity
golang fedoraproject
7.5