Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 166

Количество 166

github логотип

GHSA-g9q4-qjx4-2v7q

7 месяцев назад

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-03410

7 месяцев назад

Уязвимость языка программирования Golang, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260710-73-0027

около 1 месяца назад

Уязвимость mimir

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260209-73-0044

6 месяцев назад

Уязвимость golang

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-61729

8 месяцев назад

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-61729

8 месяцев назад

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-61729

8 месяцев назад

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-61729

8 месяцев назад

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

EPSS: Низкий
debian логотип

CVE-2025-61729

8 месяцев назад

Within HostnameError.Error(), when constructing an error string, there ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-68121

6 месяцев назад

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2025-68121

6 месяцев назад

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2025-68121

6 месяцев назад

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 10
EPSS: Низкий
msrc логотип

CVE-2025-68121

5 месяцев назад

Unexpected session resumption in crypto/tls

EPSS: Низкий
debian логотип

CVE-2025-68121

6 месяцев назад

During session resumption in crypto/tls, if the underlying Config has ...

CVSS3: 10
EPSS: Низкий
rocky логотип

RLSA-2026:2323

6 месяцев назад

Important: git-lfs security update

EPSS: Низкий
rocky логотип

RLSA-2026:2124

3 месяца назад

Important: osbuild-composer security update

EPSS: Низкий
rocky логотип

RLSA-2026:1908

6 месяцев назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:1715

6 месяцев назад

Important: golang-github-openprinting-ipp-usb security update

EPSS: Низкий
rocky логотип

RLSA-2026:1518

6 месяцев назад

Important: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2026:1344

7 месяцев назад

Important: grafana security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g9q4-qjx4-2v7q

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.

CVSS3: 6.5
1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-03410

Уязвимость языка программирования Golang, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
1%
Низкий
7 месяцев назад
redos логотип
ROS-20260710-73-0027

Уязвимость mimir

CVSS3: 6.5
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260209-73-0044

Уязвимость golang

CVSS3: 6.5
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-61729

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-61729

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-61729

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
msrc логотип
CVE-2025-61729

Excessive resource consumption when printing error string for host certificate validation in crypto/x509

0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-61729

Within HostnameError.Error(), when constructing an error string, there ...

CVSS3: 7.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 10
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 7.4
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.

CVSS3: 10
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-68121

Unexpected session resumption in crypto/tls

1%
Низкий
5 месяцев назад
debian логотип
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has ...

CVSS3: 10
1%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:2323

Important: git-lfs security update

0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:2124

Important: osbuild-composer security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:1908

Important: opentelemetry-collector security update

0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:1715

Important: golang-github-openprinting-ipp-usb security update

0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:1518

Important: grafana-pcp security update

0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:1344

Important: grafana security update

0%
Низкий
7 месяцев назад

Уязвимостей на страницу