Количество 166
Количество 166
GHSA-g9q4-qjx4-2v7q
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.
BDU:2026-03410
Уязвимость языка программирования Golang, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260710-73-0027
Уязвимость mimir
ROS-20260209-73-0044
Уязвимость golang
CVE-2025-61729
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.
CVE-2025-61729
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.
CVE-2025-61729
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.
CVE-2025-61729
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-61729
Within HostnameError.Error(), when constructing an error string, there ...
CVE-2025-68121
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.
CVE-2025-68121
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.
CVE-2025-68121
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.
CVE-2025-68121
Unexpected session resumption in crypto/tls
CVE-2025-68121
During session resumption in crypto/tls, if the underlying Config has ...
RLSA-2026:2323
Important: git-lfs security update
RLSA-2026:2124
Important: osbuild-composer security update
RLSA-2026:1908
Important: opentelemetry-collector security update
RLSA-2026:1715
Important: golang-github-openprinting-ipp-usb security update
RLSA-2026:1518
Important: grafana-pcp security update
RLSA-2026:1344
Important: grafana security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g9q4-qjx4-2v7q archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive. | CVSS3: 6.5 | 1% Низкий | 7 месяцев назад | |
BDU:2026-03410 Уязвимость языка программирования Golang, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 1% Низкий | 7 месяцев назад | |
ROS-20260710-73-0027 Уязвимость mimir | CVSS3: 6.5 | 1% Низкий | около 1 месяца назад | |
ROS-20260209-73-0044 Уязвимость golang | CVSS3: 6.5 | 1% Низкий | 6 месяцев назад | |
CVE-2025-61729 Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-61729 Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-61729 Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509 | 0% Низкий | 8 месяцев назад | ||
CVE-2025-61729 Within HostnameError.Error(), when constructing an error string, there ... | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake. | CVSS3: 10 | 1% Низкий | 6 месяцев назад | |
CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake. | CVSS3: 7.4 | 1% Низкий | 6 месяцев назад | |
CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake. | CVSS3: 10 | 1% Низкий | 6 месяцев назад | |
CVE-2025-68121 Unexpected session resumption in crypto/tls | 1% Низкий | 5 месяцев назад | ||
CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has ... | CVSS3: 10 | 1% Низкий | 6 месяцев назад | |
RLSA-2026:2323 Important: git-lfs security update | 0% Низкий | 6 месяцев назад | ||
RLSA-2026:2124 Important: osbuild-composer security update | 0% Низкий | 3 месяца назад | ||
RLSA-2026:1908 Important: opentelemetry-collector security update | 0% Низкий | 6 месяцев назад | ||
RLSA-2026:1715 Important: golang-github-openprinting-ipp-usb security update | 0% Низкий | 6 месяцев назад | ||
RLSA-2026:1518 Important: grafana-pcp security update | 0% Низкий | 6 месяцев назад | ||
RLSA-2026:1344 Important: grafana security update | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу