Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 233

Количество 233

github логотип

GHSA-m4pr-4j3g-9v7v

6 месяцев назад

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07254

6 месяцев назад

Уязвимость компонента crypto-x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2026-4231

7 месяцев назад

ALT-PU-2026-4231: package `golang` update to version 1.25.8-alt1

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3151-1

2 месяца назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3046-1

3 месяца назад

Security update for go1.25-openssl

EPSS: Низкий
redos логотип

ROS-20260710-80-0005

3 месяца назад

Уязвимость mimir

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260710-73-0005

3 месяца назад

Уязвимость mimir

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260507-73-0012

5 месяцев назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:49838

около 2 месяцев назад

Important: osbuild-composer security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:49526

около 2 месяцев назад

Important: osbuild-composer security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-49838

около 2 месяцев назад

ELSA-2026-49838: osbuild-composer security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-49526

около 2 месяцев назад

ELSA-2026-49526: osbuild-composer security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20703-1

5 месяцев назад

Security update for coredns

EPSS: Низкий
ubuntu логотип

CVE-2026-32282

6 месяцев назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2026-32282

6 месяцев назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-32282

6 месяцев назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2026-32282

6 месяцев назад

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

EPSS: Низкий
debian логотип

CVE-2026-32282

6 месяцев назад

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2026-32283

6 месяцев назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-32283

6 месяцев назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m4pr-4j3g-9v7v

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

CVSS3: 7.5
6 месяцев назад
fstec логотип
BDU:2026-07254

Уязвимость компонента crypto-x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
6 месяцев назад
altlinux логотип
ALT-PU-2026-4231

ALT-PU-2026-4231: package `golang` update to version 1.25.8-alt1

CVSS3: 7.5
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3151-1

Security update for go1.25-openssl

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3046-1

Security update for go1.25-openssl

3 месяца назад
redos логотип
ROS-20260710-80-0005

Уязвимость mimir

CVSS3: 7.5
3 месяца назад
redos логотип
ROS-20260710-73-0005

Уязвимость mimir

CVSS3: 7.5
3 месяца назад
redos логотип
ROS-20260507-73-0012

Уязвимость golang

CVSS3: 7.5
5 месяцев назад
rocky логотип
RLSA-2026:49838

Important: osbuild-composer security, bug fix, and enhancement update

около 2 месяцев назад
rocky логотип
RLSA-2026:49526

Important: osbuild-composer security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-49838

ELSA-2026-49838: osbuild-composer security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-49526

ELSA-2026-49526: osbuild-composer security update (IMPORTANT)

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20703-1

Security update for coredns

5 месяцев назад
ubuntu логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
6 месяцев назад
redhat логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
6 месяцев назад
nvd логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
6 месяцев назад
msrc логотип
CVE-2026-32282

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

6 месяцев назад
debian логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
6 месяцев назад
ubuntu логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
6 месяцев назад
redhat логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
6 месяцев назад

Уязвимостей на страницу