Golang

Go

173 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.08%
  • Veröffentlicht 10.08.2022 20:15:40
  • Zuletzt bearbeitet 06.03.2026 20:16:10

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

  • EPSS 1.94%
  • Veröffentlicht 10.08.2022 20:15:40
  • Zuletzt bearbeitet 06.03.2026 18:16:13

Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.

  • EPSS 2.12%
  • Veröffentlicht 10.08.2022 20:15:34
  • Zuletzt bearbeitet 21.11.2024 06:59:42

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

  • EPSS 2.27%
  • Veröffentlicht 10.08.2022 20:15:32
  • Zuletzt bearbeitet 21.11.2024 06:56:48

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 10.08.2022 20:15:26
  • Zuletzt bearbeitet 06.03.2026 20:16:09

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

Exploit
  • EPSS 1.37%
  • Veröffentlicht 10.08.2022 20:15:25
  • Zuletzt bearbeitet 06.03.2026 18:16:10

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

Exploit
  • EPSS 2.06%
  • Veröffentlicht 15.07.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:04

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

Exploit
  • EPSS 2.79%
  • Veröffentlicht 23.06.2022 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:59:15

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

  • EPSS 4.2%
  • Veröffentlicht 20.04.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:10

The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

  • EPSS 9.95%
  • Veröffentlicht 20.04.2022 10:15:07
  • Zuletzt bearbeitet 21.11.2024 06:50:50

encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.