Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 125

Количество 125

oracle-oval логотип

ELSA-2026-46395

4 дня назад

ELSA-2026-46395: go-fdo-server security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39573

16 дней назад

Important: yggdrasil security update

EPSS: Низкий
rocky логотип

RLSA-2026:38995

16 дней назад

Important: go-toolset:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39573

15 дней назад

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-38995

17 дней назад

ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:34359

26 дней назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

24 дня назад

Important: opentelemetry-collector security update

EPSS: Низкий
ubuntu логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-27145

около 2 месяцев назад

Inefficient candidate hostname parsing in crypto/x509

EPSS: Низкий
debian логотип

CVE-2026-27145

около 2 месяцев назад

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
msrc логотип

CVE-2026-39821

2 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2026-39821

2 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4279-q6mj-392r

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-46394

4 дня назад

ELSA-2026-46394: go-fdo-client security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09275

около 2 месяцев назад

Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-46395

ELSA-2026-46395: go-fdo-server security update (IMPORTANT)

4 дня назад
rocky логотип
RLSA-2026:39573

Important: yggdrasil security update

16 дней назад
rocky логотип
RLSA-2026:38995

Important: go-toolset:rhel8 security, bug fix, and enhancement update

16 дней назад
oracle-oval логотип
ELSA-2026-39573

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2026-38995

ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)

17 дней назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

26 дней назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

24 дня назад
ubuntu логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509

1%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-27145

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
1%
Низкий
2 месяца назад
github логотип
GHSA-4279-q6mj-392r

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46394

ELSA-2026-46394: go-fdo-client security update (IMPORTANT)

4 дня назад
fstec логотип
BDU:2026-09275

Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу