Логотип exploitDog
bind: "CVE-2025-68119"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-68119"

Количество 21

Количество 21

ubuntu логотип

CVE-2025-68119

2 месяца назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2025-68119

2 месяца назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2025-68119

2 месяца назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2025-68119

2 месяца назад

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-cm6p-qc7v-m3jw

2 месяца назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
fstec логотип

BDU:2026-03601

2 месяца назад

Уязвимость языка программирования Golang, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
EPSS: Низкий
redos логотип

ROS-20260209-73-0047

около 2 месяцев назад

Уязвимость golang

CVSS3: 7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20220-1

около 2 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0789-1

около 1 месяца назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0687-1

около 1 месяца назад

Security update for go1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0426-1

около 2 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20085-1

2 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20077-1

2 месяца назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0219-1

2 месяца назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0218-1

2 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20301-1

около 1 месяца назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0308-1

2 месяца назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0296-1

2 месяца назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20308-1

около 1 месяца назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0298-1

2 месяца назад

Security update for go1.25-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 6.7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
0%
Низкий
2 месяца назад
github логотип
GHSA-cm6p-qc7v-m3jw

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-03601

Уязвимость языка программирования Golang, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
0%
Низкий
2 месяца назад
redos логотип
ROS-20260209-73-0047

Уязвимость golang

CVSS3: 7
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20220-1

Security update for go1.24

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0789-1

Security update for go1.24-openssl

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0687-1

Security update for go1

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0426-1

Security update for go1.24

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20085-1

Security update for go1.25

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20077-1

Security update for go1.24

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0219-1

Security update for go1.24

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0218-1

Security update for go1.25

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20301-1

Security update for go1.25-openssl

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0308-1

Security update for go1.24-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0296-1

Security update for go1.24-openssl

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20308-1

Security update for go1.24-openssl

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0298-1

Security update for go1.25-openssl

2 месяца назад

Уязвимостей на страницу