Количество 184
Количество 184
CVE-2026-27145
*x509.Certificate).VerifyHostname previously called matchHostnames in ...
RLSA-2026:46394
Important: go-fdo-client security update
GHSA-4279-q6mj-392r
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
ELSA-2026-46394
ELSA-2026-46394: go-fdo-client security update (IMPORTANT)
BDU:2026-09275
Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260710-80-0030
Уязвимость mimir
ROS-20260710-73-0030
Уязвимость mimir
ROS-20260707-80-0034
Уязвимость golang
ROS-20260707-73-0036
Уязвимость golang
RLSA-2026:36317
Important: skopeo security update
RLSA-2026:35832
Important: golang-github-openprinting-ipp-usb security update
RLSA-2026:29981
Moderate: golang security, bug fix, and enhancement update
ELSA-2026-36317
ELSA-2026-36317: skopeo security update (IMPORTANT)
ELSA-2026-35832
ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)
openSUSE-SU-2026:21319-1
Security update for go1.25-openssl
CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
CVE-2026-39822
Root escape via symlink plus trailing slash in os
CVE-2026-39822
On Unix systems, opening a file in an os.Root improperly follows symli ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-27145 *x509.Certificate).VerifyHostname previously called matchHostnames in ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
RLSA-2026:46394 Important: go-fdo-client security update | 1% Низкий | около 2 месяцев назад | ||
GHSA-4279-q6mj-392r (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
ELSA-2026-46394 ELSA-2026-46394: go-fdo-client security update (IMPORTANT) | 1% Низкий | около 2 месяцев назад | ||
BDU:2026-09275 Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
ROS-20260710-80-0030 Уязвимость mimir | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
ROS-20260710-73-0030 Уязвимость mimir | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
ROS-20260707-80-0034 Уязвимость golang | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
ROS-20260707-73-0036 Уязвимость golang | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
RLSA-2026:36317 Important: skopeo security update | 2 месяца назад | |||
RLSA-2026:35832 Important: golang-github-openprinting-ipp-usb security update | 2 месяца назад | |||
RLSA-2026:29981 Moderate: golang security, bug fix, and enhancement update | 3 месяца назад | |||
ELSA-2026-36317 ELSA-2026-36317: skopeo security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-35832 ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT) | 2 месяца назад | |||
openSUSE-SU-2026:21319-1 Security update for go1.25-openssl | 2 месяца назад | |||
CVE-2026-39822 On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-39822 On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-39822 On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-39822 Root escape via symlink plus trailing slash in os | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-39822 On Unix systems, opening a file in an os.Root improperly follows symli ... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу