Vulnerabilities > Golang

DATE CVE VULNERABILITY TITLE RISK
2022-08-10 CVE-2022-29804 Path Traversal vulnerability in Golang GO
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
network
low complexity
golang CWE-22
7.5
2022-08-10 CVE-2022-30580 Code Injection vulnerability in Golang GO
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
local
low complexity
golang CWE-94
7.8
2022-08-10 CVE-2022-30629 Use of Insufficiently Random Values vulnerability in Golang GO
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
network
high complexity
golang CWE-330
3.1
2022-08-10 CVE-2022-30630 Uncontrolled Recursion vulnerability in Golang GO
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
network
low complexity
golang CWE-674
7.5
2022-08-10 CVE-2022-30631 Uncontrolled Recursion vulnerability in Golang GO
Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.
network
low complexity
golang CWE-674
7.5
2022-08-10 CVE-2022-30632 Uncontrolled Recursion vulnerability in Golang GO
Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.
network
low complexity
golang CWE-674
7.5
2022-08-10 CVE-2022-30633 Uncontrolled Recursion vulnerability in Golang GO
Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag.
network
low complexity
golang CWE-674
7.5
2022-08-10 CVE-2022-30635 Uncontrolled Recursion vulnerability in Golang GO
Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.
network
low complexity
golang CWE-674
7.5
2022-08-10 CVE-2022-32148 Unspecified vulnerability in Golang GO
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
network
low complexity
golang
6.5
2022-08-10 CVE-2022-32189 Unspecified vulnerability in Golang GO
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
network
low complexity
golang
7.5