Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 144

Количество 144

github логотип

GHSA-4279-q6mj-392r

около 2 месяцев назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-46394

4 дня назад

ELSA-2026-46394: go-fdo-client security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09275

около 2 месяцев назад

Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260710-73-0030

21 день назад

Уязвимость mimir

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260707-73-0036

24 дня назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:36317

23 дня назад

Important: skopeo security update

EPSS: Низкий
rocky логотип

RLSA-2026:35832

24 дня назад

Important: golang-github-openprinting-ipp-usb security update

EPSS: Низкий
rocky логотип

RLSA-2026:29981

около 1 месяца назад

Moderate: golang security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36317

24 дня назад

ELSA-2026-36317: skopeo security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35832

15 дней назад

ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21319-1

18 дней назад

Security update for go1.25-openssl

EPSS: Низкий
ubuntu логотип

CVE-2026-39822

22 дня назад

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-39822

23 дня назад

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-39822

22 дня назад

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-39822

16 дней назад

Root escape via symlink plus trailing slash in os

EPSS: Низкий
debian логотип

CVE-2026-39822

22 дня назад

On Unix systems, opening a file in an os.Root improperly follows symli ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20977-1

около 1 месяца назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20976-1

около 1 месяца назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2327-1

около 2 месяцев назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2326-1

около 2 месяцев назад

Security update for go1.25

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4279-q6mj-392r

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46394

ELSA-2026-46394: go-fdo-client security update (IMPORTANT)

4 дня назад
fstec логотип
BDU:2026-09275

Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260710-73-0030

Уязвимость mimir

CVSS3: 7.5
1%
Низкий
21 день назад
redos логотип
ROS-20260707-73-0036

Уязвимость golang

CVSS3: 7.5
1%
Низкий
24 дня назад
rocky логотип
RLSA-2026:36317

Important: skopeo security update

23 дня назад
rocky логотип
RLSA-2026:35832

Important: golang-github-openprinting-ipp-usb security update

24 дня назад
rocky логотип
RLSA-2026:29981

Moderate: golang security, bug fix, and enhancement update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-36317

ELSA-2026-36317: skopeo security update (IMPORTANT)

24 дня назад
oracle-oval логотип
ELSA-2026-35832

ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21319-1

Security update for go1.25-openssl

18 дней назад
ubuntu логотип
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
0%
Низкий
22 дня назад
redhat логотип
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

CVSS3: 7.8
0%
Низкий
22 дня назад
msrc логотип
CVE-2026-39822

Root escape via symlink plus trailing slash in os

0%
Низкий
16 дней назад
debian логотип
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symli ...

CVSS3: 7.8
0%
Низкий
22 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20977-1

Security update for go1.25

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20976-1

Security update for go1.26

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2327-1

Security update for go1.26

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2326-1

Security update for go1.25

около 2 месяцев назад

Уязвимостей на страницу