Количество 22
Количество 22
BDU:2026-09275
Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260710-73-0030
Уязвимость mimir
ROS-20260707-73-0036
Уязвимость golang
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-27145
*x509.Certificate).VerifyHostname previously called matchHostnames in ...
GHSA-4279-q6mj-392r
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
RLSA-2026:36317
Important: skopeo security update
RLSA-2026:35832
Important: golang-github-openprinting-ipp-usb security update
RLSA-2026:29981
Moderate: golang security, bug fix, and enhancement update
ELSA-2026-36317
ELSA-2026-36317: skopeo security update (IMPORTANT)
openSUSE-SU-2026:20977-1
Security update for go1.25
openSUSE-SU-2026:20976-1
Security update for go1.26
SUSE-SU-2026:2327-1
Security update for go1.26
SUSE-SU-2026:2326-1
Security update for go1.25
RLSA-2026:38995
Important: go-toolset:rhel8 security, bug fix, and enhancement update
ELSA-2026-38995
ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:34359
Important: opentelemetry-collector security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-09275 Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
ROS-20260710-73-0030 Уязвимость mimir | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
ROS-20260707-73-0036 Уязвимость golang | CVSS3: 7.5 | 1% Низкий | 24 дня назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-27145 *x509.Certificate).VerifyHostname previously called matchHostnames in ... | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
GHSA-4279-q6mj-392r (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
RLSA-2026:36317 Important: skopeo security update | 23 дня назад | |||
RLSA-2026:35832 Important: golang-github-openprinting-ipp-usb security update | 24 дня назад | |||
RLSA-2026:29981 Moderate: golang security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-36317 ELSA-2026-36317: skopeo security update (IMPORTANT) | 24 дня назад | |||
openSUSE-SU-2026:20977-1 Security update for go1.25 | около 1 месяца назад | |||
openSUSE-SU-2026:20976-1 Security update for go1.26 | около 1 месяца назад | |||
SUSE-SU-2026:2327-1 Security update for go1.26 | около 2 месяцев назад | |||
SUSE-SU-2026:2326-1 Security update for go1.25 | около 2 месяцев назад | |||
RLSA-2026:38995 Important: go-toolset:rhel8 security, bug fix, and enhancement update | 16 дней назад | |||
ELSA-2026-38995 ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT) | 17 дней назад | |||
RLSA-2026:34359 Important: opentelemetry-collector security update | 26 дней назад |
Уязвимостей на страницу