Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 84

Количество 84

fstec логотип

BDU:2026-07950

4 месяца назад

Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-57231

около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-57231

около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57231

около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-57231

около 1 месяца назад

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

EPSS: Низкий
debian логотип

CVE-2026-57231

около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 unti ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260710-73-0007

21 день назад

Уязвимость mimir

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260622-73-0032

около 1 месяца назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:35832

24 дня назад

Important: golang-github-openprinting-ipp-usb security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35832

15 дней назад

ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39573

16 дней назад

Important: yggdrasil security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39573

15 дней назад

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-39835

2 месяца назад

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without set ...

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2026:34359

26 дней назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

24 дня назад

Important: opentelemetry-collector security update

EPSS: Низкий
github логотип

GHSA-78mq-xcr3-xm33

около 1 месяца назад

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-07950

Уязвимость функций LookupCNAME() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-57231

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-57231

Podman is a tool for managing OCI containers and pods. From 1.8.1 unti ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260710-73-0007

Уязвимость mimir

CVSS3: 7.5
1%
Низкий
21 день назад
redos логотип
ROS-20260622-73-0032

Уязвимость golang

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:35832

Important: golang-github-openprinting-ipp-usb security update

24 дня назад
oracle-oval логотип
ELSA-2026-35832

ELSA-2026-35832: golang-github-openprinting-ipp-usb security update (IMPORTANT)

15 дней назад
rocky логотип
RLSA-2026:39573

Important: yggdrasil security update

16 дней назад
oracle-oval логотип
ELSA-2026-39573

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

15 дней назад
ubuntu логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39835

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without set ...

CVSS3: 5.3
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

26 дней назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

24 дня назад
github логотип
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CVSS3: 5.3
1%
Низкий
около 1 месяца назад

Уязвимостей на страницу