Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 111

Количество 111

rocky логотип

RLSA-2026:3428

4 месяца назад

Important: container-tools:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3428

4 месяца назад

ELSA-2026-3428: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2024-24785

4 месяца назад

Errors returned from JSON marshaling may break template escaping in html/template

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled da ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j6m3-gc37-6r6q

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2024-03248

больше 2 лет назад

Уязвимость пакета html/template языка программирования Go, связанная с отсутствием проверки входных значений, позволяющая нарушителю вводить произвольный контент в шаблоны

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-65637

7 месяцев назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-65637

7 месяцев назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-65637

7 месяцев назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-65637

7 месяцев назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2025-65637

7 месяцев назад

A denial-of-service vulnerability exists in github.com/sirupsen/logrus ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2024:9135

больше 1 года назад

Moderate: toolbox security update

EPSS: Низкий
github логотип

GHSA-4f99-4q7p-p3gh

7 месяцев назад

Logrus is vulnerable to DoS when using Entry.Writer()

EPSS: Низкий
fstec логотип

BDU:2026-06592

больше 3 лет назад

Уязвимость функции Entry.Writer() библиотеки логирования Logrus, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0936-1

больше 2 лет назад

Security update for go1.22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0812-1

больше 2 лет назад

Security update for go1.22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0811-1

больше 2 лет назад

Security update for go1.21

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:3428

Important: container-tools:rhel8 security update

4 месяца назад
oracle-oval логотип
ELSA-2026-3428

ELSA-2026-3428: container-tools:ol8 security update (IMPORTANT)

4 месяца назад
ubuntu логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-24785

Errors returned from JSON marshaling may break template escaping in html/template

CVSS3: 5.4
1%
Низкий
4 месяца назад
debian логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled da ...

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-j6m3-gc37-6r6q

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-03248

Уязвимость пакета html/template языка программирования Go, связанная с отсутствием проверки входных значений, позволяющая нарушителю вводить произвольный контент в шаблоны

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
msrc логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters.

CVSS3: 5.9
1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus ...

CVSS3: 7.5
1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2024:9135

Moderate: toolbox security update

больше 1 года назад
github логотип
GHSA-4f99-4q7p-p3gh

Logrus is vulnerable to DoS when using Entry.Writer()

1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-06592

Уязвимость функции Entry.Writer() библиотеки логирования Logrus, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2024:0936-1

Security update for go1.22

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0812-1

Security update for go1.22

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0811-1

Security update for go1.21

больше 2 лет назад

Уязвимостей на страницу