Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 130

Количество 130

redhat логотип

CVE-2026-33810

4 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-33810

4 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2026-33810

4 месяца назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-33810

4 месяца назад

When verifying a certificate chain containing excluded DNS constraints ...

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260729-73-0017

14 дней назад

Уязвимость coredns

CVSS3: 6.4
EPSS: Низкий
redos логотип

ROS-20260710-73-0031

около 1 месяца назад

Уязвимость mimir

CVSS3: 6.4
EPSS: Низкий
redos логотип

ROS-20260430-73-0011

3 месяца назад

Уязвимость golang

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2026-32283

4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-32283

4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-32283

4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-32283

4 месяца назад

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

EPSS: Низкий
debian логотип

CVE-2026-32283

4 месяца назад

If one side of the TLS connection sends multiple key update messages p ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fv83-x2xw-2j55

4 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07331

4 месяца назад

Уязвимость пакета crypto/x509 языка программирования Go, позволяющая нарушителю проводить атаки типа "человек посередине"

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260729-73-0029

14 дней назад

Уязвимость coredns

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260430-73-0016

3 месяца назад

Уязвимость golang

CVSS3: 8.2
EPSS: Низкий
rocky логотип

RLSA-2026:19139

2 месяца назад

Important: go-fdo-client security update

EPSS: Низкий
rocky логотип

RLSA-2026:11881

3 месяца назад

Important: grafana-pcp security update

EPSS: Низкий
github логотип

GHSA-jrg3-gfjw-hm96

4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19139

26 дней назад

ELSA-2026-19139: go-fdo-client security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-33810

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 5.9
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints ...

CVSS3: 8.2
0%
Низкий
4 месяца назад
redos логотип
ROS-20260729-73-0017

Уязвимость coredns

CVSS3: 6.4
0%
Низкий
14 дней назад
redos логотип
ROS-20260710-73-0031

Уязвимость mimir

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260430-73-0011

Уязвимость golang

CVSS3: 6.4
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-32283

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages p ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-fv83-x2xw-2j55

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07331

Уязвимость пакета crypto/x509 языка программирования Go, позволяющая нарушителю проводить атаки типа "человек посередине"

CVSS3: 8.2
0%
Низкий
4 месяца назад
redos логотип
ROS-20260729-73-0029

Уязвимость coredns

CVSS3: 8.2
0%
Низкий
14 дней назад
redos логотип
ROS-20260430-73-0016

Уязвимость golang

CVSS3: 8.2
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:19139

Important: go-fdo-client security update

1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:11881

Important: grafana-pcp security update

1%
Низкий
3 месяца назад
github логотип
GHSA-jrg3-gfjw-hm96

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19139

ELSA-2026-19139: go-fdo-client security update (IMPORTANT)

1%
Низкий
26 дней назад

Уязвимостей на страницу