Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 41

Количество 41

rocky логотип

RLSA-2026:29981

около 1 месяца назад

Moderate: golang security, bug fix, and enhancement update

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20977-1

около 1 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20976-1

около 1 месяца назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2327-1

около 2 месяцев назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2326-1

около 2 месяцев назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3102-1

14 дней назад

Security update for go1.26-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3047-1

16 дней назад

Security update for go1.26-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3151-1

10 дней назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3046-1

16 дней назад

Security update for go1.25-openssl

EPSS: Низкий
ubuntu логотип

CVE-2026-42507

около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-42507

около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-42507

около 2 месяцев назад

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-42507

около 2 месяцев назад

Arbitrary inputs are included in errors without any escaping in net/textproto

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-42507

около 2 месяцев назад

When returning errors, functions in the net/textproto package would in ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27145

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-27145

около 2 месяцев назад

Inefficient candidate hostname parsing in crypto/x509

EPSS: Низкий
debian логотип

CVE-2026-27145

около 2 месяцев назад

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21254-1

24 дня назад

Security update for go1.26-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:29981

Moderate: golang security, bug fix, and enhancement update

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20977-1

Security update for go1.25

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20976-1

Security update for go1.26

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2327-1

Security update for go1.26

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2326-1

Security update for go1.25

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3102-1

Security update for go1.26-openssl

14 дней назад
suse-cvrf логотип
SUSE-SU-2026:3047-1

Security update for go1.26-openssl

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:3151-1

Security update for go1.25-openssl

10 дней назад
suse-cvrf логотип
SUSE-SU-2026:3046-1

Security update for go1.25-openssl

16 дней назад
ubuntu логотип
CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-42507

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-42507

Arbitrary inputs are included in errors without any escaping in net/textproto

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-42507

When returning errors, functions in the net/textproto package would in ...

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509

1%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-27145

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21254-1

Security update for go1.26-openssl

24 дня назад

Уязвимостей на страницу