Количество 51
Количество 51
RLSA-2026:29981
Moderate: golang security, bug fix, and enhancement update
openSUSE-SU-2026:20977-1
Security update for go1.25
openSUSE-SU-2026:20976-1
Security update for go1.26
SUSE-SU-2026:2327-1
Security update for go1.26
SUSE-SU-2026:2326-1
Security update for go1.25
SUSE-SU-2026:3102-1
Security update for go1.26-openssl
SUSE-SU-2026:3047-1
Security update for go1.26-openssl
SUSE-SU-2026:3151-1
Security update for go1.25-openssl
SUSE-SU-2026:3046-1
Security update for go1.25-openssl
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
Arbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-42507
When returning errors, functions in the net/textproto package would in ...
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-27145
*x509.Certificate).VerifyHostname previously called matchHostnames in ...
openSUSE-SU-2026:21254-1
Security update for go1.26-openssl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:29981 Moderate: golang security, bug fix, and enhancement update | 3 месяца назад | |||
openSUSE-SU-2026:20977-1 Security update for go1.25 | 3 месяца назад | |||
openSUSE-SU-2026:20976-1 Security update for go1.26 | 3 месяца назад | |||
SUSE-SU-2026:2327-1 Security update for go1.26 | 3 месяца назад | |||
SUSE-SU-2026:2326-1 Security update for go1.25 | 3 месяца назад | |||
SUSE-SU-2026:3102-1 Security update for go1.26-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3047-1 Security update for go1.26-openssl | 2 месяца назад | |||
SUSE-SU-2026:3151-1 Security update for go1.25-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3046-1 Security update for go1.25-openssl | 2 месяца назад | |||
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would in ... | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | 3 месяца назад | ||
CVE-2026-27145 *x509.Certificate).VerifyHostname previously called matchHostnames in ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21254-1 Security update for go1.26-openssl | 2 месяца назад |
Уязвимостей на страницу