Количество 132
Количество 132
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVE-2026-32281
Inefficient policy validation in crypto/x509
CVE-2026-32281
Validating certificate chains which use policies is unexpectedly ineff ...
CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
CVE-2026-32282
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while ...
ROS-20260430-80-0008
Уязвимость golang
RLSA-2026:27740
Moderate: golang-github-openprinting-ipp-usb security update
GHSA-gjvh-7jh8-7xhm
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
ELSA-2026-27740
ELSA-2026-27740: golang-github-openprinting-ipp-usb security update (MODERATE)
BDU:2026-07251
Уязвимость языка программирования Go, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260430-80-0011
Уязвимость golang
RLSA-2026:25999
Moderate: yggdrasil-worker-package-manager security update
GHSA-xj38-jxc5-rppx
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
ELSA-2026-25999
ELSA-2026-25999: yggdrasil-worker-package-manager security update (MODERATE)
BDU:2026-07252
Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии
ROS-20260710-80-0006
Уязвимость mimir
ROS-20260710-73-0006
Уязвимость mimir
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32281 Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32281 Inefficient policy validation in crypto/x509 | 0% Низкий | 6 месяцев назад | ||
CVE-2026-32281 Validating certificate chains which use policies is unexpectedly ineff ... | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation. | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation. | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation. | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix | 0% Низкий | 6 месяцев назад | ||
CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while ... | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
ROS-20260430-80-0008 Уязвимость golang | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
RLSA-2026:27740 Moderate: golang-github-openprinting-ipp-usb security update | 0% Низкий | 3 месяца назад | ||
GHSA-gjvh-7jh8-7xhm Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool. | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
ELSA-2026-27740 ELSA-2026-27740: golang-github-openprinting-ipp-usb security update (MODERATE) | 0% Низкий | 2 месяца назад | ||
BDU:2026-07251 Уязвимость языка программирования Go, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
ROS-20260430-80-0011 Уязвимость golang | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
RLSA-2026:25999 Moderate: yggdrasil-worker-package-manager security update | 0% Низкий | 3 месяца назад | ||
GHSA-xj38-jxc5-rppx On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation. | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
ELSA-2026-25999 ELSA-2026-25999: yggdrasil-worker-package-manager security update (MODERATE) | 0% Низкий | 2 месяца назад | ||
BDU:2026-07252 Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
ROS-20260710-80-0006 Уязвимость mimir | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ROS-20260710-73-0006 Уязвимость mimir | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу