Количество 154
Количество 154
RLSA-2026:36317
Important: skopeo security update
ELSA-2026-36317
ELSA-2026-36317: skopeo security update (IMPORTANT)
SUSE-SU-2026:3151-1
Security update for go1.25-openssl
SUSE-SU-2026:3046-1
Security update for go1.25-openssl
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-27145
*x509.Certificate).VerifyHostname previously called matchHostnames in ...
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-25679
Incorrect parsing of IPv6 host literals in net/url
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and ac ...
RLSA-2026:46394
Important: go-fdo-client security update
GHSA-4279-q6mj-392r
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
ELSA-2026-46394
ELSA-2026-46394: go-fdo-client security update (IMPORTANT)
BDU:2026-09275
Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:21319-1
Security update for go1.25-openssl
ROS-20260710-80-0030
Уязвимость mimir
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:36317 Important: skopeo security update | 2 месяца назад | |||
ELSA-2026-36317 ELSA-2026-36317: skopeo security update (IMPORTANT) | 2 месяца назад | |||
SUSE-SU-2026:3151-1 Security update for go1.25-openssl | около 2 месяцев назад | |||
SUSE-SU-2026:3046-1 Security update for go1.25-openssl | 2 месяца назад | |||
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | 3 месяца назад | ||
CVE-2026-27145 *x509.Certificate).VerifyHostname previously called matchHostnames in ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-25679 url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-25679 url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-25679 url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url | 1% Низкий | 6 месяцев назад | ||
CVE-2026-25679 url.Parse insufficiently validated the host/authority component and ac ... | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
RLSA-2026:46394 Important: go-fdo-client security update | 1% Низкий | около 2 месяцев назад | ||
GHSA-4279-q6mj-392r (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
ELSA-2026-46394 ELSA-2026-46394: go-fdo-client security update (IMPORTANT) | 1% Низкий | около 2 месяцев назад | ||
BDU:2026-09275 Уязвимость компонента crypto/x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21319-1 Security update for go1.25-openssl | 2 месяца назад | |||
ROS-20260710-80-0030 Уязвимость mimir | CVSS3: 7.5 | 1% Низкий | 2 месяца назад |
Уязвимостей на страницу