CVE-2026-27144
- EPSS 0.26%
- Veröffentlicht 08.04.2026 01:06:56
- Zuletzt bearbeitet 25.07.2026 10:10:00
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runti...
CVE-2026-32289
- EPSS 0.29%
- Veröffentlicht 08.04.2026 01:06:56
- Zuletzt bearbeitet 25.07.2026 10:10:00
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace ...
CVE-2026-33810
- EPSS 0.34%
- Veröffentlicht 08.04.2026 01:06:56
- Zuletzt bearbeitet 18.09.2026 13:17:56
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate cha...
CVE-2026-32282
- EPSS 0.29%
- Veröffentlicht 08.04.2026 01:06:55
- Zuletzt bearbeitet 25.07.2026 10:10:00
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_...
CVE-2026-25679
- EPSS 0.73%
- Veröffentlicht 06.03.2026 21:28:14
- Zuletzt bearbeitet 18.09.2026 13:17:30
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-27138
- EPSS 0.35%
- Veröffentlicht 06.03.2026 21:28:14
- Zuletzt bearbeitet 21.04.2026 14:39:28
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those...
CVE-2026-27139
- EPSS 0.2%
- Veröffentlicht 06.03.2026 21:28:14
- Zuletzt bearbeitet 21.04.2026 14:32:36
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata pro...
CVE-2026-27142
- EPSS 0.33%
- Veröffentlicht 06.03.2026 21:28:14
- Zuletzt bearbeitet 21.04.2026 14:30:01
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, whic...
CVE-2026-27137
- EPSS 0.61%
- Veröffentlicht 06.03.2026 21:28:13
- Zuletzt bearbeitet 16.09.2026 13:17:27
When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constrain...
- EPSS 0.77%
- Veröffentlicht 05.02.2026 17:48:44
- Zuletzt bearbeitet 29.04.2026 14:16:16
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when ...