Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 82

Количество 82

github логотип

GHSA-vgwf-h737-ff37

3 месяца назад

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-12028

4 месяца назад

Уязвимость функции Close() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260831-80-0009

14 дней назад

Уязвимость prometheus-podman-exporter

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-39835

4 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-39835

4 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39835

4 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-39835

4 месяца назад

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-39835

4 месяца назад

SSH servers which use CertChecker as a public key callback without set ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-39832

4 месяца назад

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-39832

4 месяца назад

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2026-39832

4 месяца назад

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-39832

4 месяца назад

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-39832

4 месяца назад

When adding a key to a remote agent constraint extensions such as rest ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260901-80-0026

13 дней назад

Уязвимость prometheus-podman-exporter

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-78mq-xcr3-xm33

3 месяца назад

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260709-80-0028

2 месяца назад

Уязвимость portainer-ce

CVSS3: 8.7
EPSS: Низкий
redos логотип

ROS-20260709-73-0027

2 месяца назад

Уязвимость portainer-ce

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-f5wc-c3c7-36mc

3 месяца назад

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-12029

4 месяца назад

Уязвимость функции NewKeyring() языка программирования Go, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260831-80-0011

14 дней назад

Уязвимость prometheus-podman-exporter

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CVSS3: 9.1
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-12028

Уязвимость функции Close() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260831-80-0009

Уязвимость prometheus-podman-exporter

CVSS3: 7.5
1%
Низкий
14 дней назад
ubuntu логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-39835

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without set ...

CVSS3: 5.3
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 8.7
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-39832

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

CVSS3: 9.1
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as rest ...

CVSS3: 9.1
1%
Низкий
4 месяца назад
redos логотип
ROS-20260901-80-0026

Уязвимость prometheus-podman-exporter

CVSS3: 7.5
1%
Низкий
13 дней назад
github логотип
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

CVSS3: 5.3
1%
Низкий
3 месяца назад
redos логотип
ROS-20260709-80-0028

Уязвимость portainer-ce

CVSS3: 8.7
1%
Низкий
2 месяца назад
redos логотип
ROS-20260709-73-0027

Уязвимость portainer-ce

CVSS3: 8.7
1%
Низкий
2 месяца назад
github логотип
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

CVSS3: 9.1
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-12029

Уязвимость функции NewKeyring() языка программирования Go, позволяющая нарушителю повысить свои привилегии

CVSS3: 9.1
1%
Низкий
4 месяца назад
redos логотип
ROS-20260831-80-0011

Уязвимость prometheus-podman-exporter

CVSS3: 9.1
1%
Низкий
14 дней назад

Уязвимостей на страницу