Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 176

Количество 176

rocky логотип

RLSA-2026:46395

около 2 месяцев назад

Important: go-fdo-server security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-46395

около 2 месяцев назад

ELSA-2026-46395: go-fdo-server security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39573

2 месяца назад

Important: yggdrasil security update

EPSS: Низкий
rocky логотип

RLSA-2026:38995

2 месяца назад

Important: go-toolset:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39573

2 месяца назад

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-38995

2 месяца назад

ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:34359

2 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
rocky логотип

RLSA-2026:34357

2 месяца назад

Important: opentelemetry-collector security update

EPSS: Низкий
ubuntu логотип

CVE-2026-27145

3 месяца назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-27145

3 месяца назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27145

3 месяца назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-27145

3 месяца назад

Inefficient candidate hostname parsing in crypto/x509

EPSS: Низкий
debian логотип

CVE-2026-27145

3 месяца назад

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
EPSS: Низкий
msrc логотип

CVE-2026-39821

4 месяца назад

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2026-39821

4 месяца назад

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
EPSS: Низкий
rocky логотип

RLSA-2026:46394

около 2 месяцев назад

Important: go-fdo-client security update

EPSS: Низкий
github логотип

GHSA-4279-q6mj-392r

3 месяца назад

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:46395

Important: go-fdo-server security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-46395

ELSA-2026-46395: go-fdo-server security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:39573

Important: yggdrasil security update

2 месяца назад
rocky логотип
RLSA-2026:38995

Important: go-toolset:rhel8 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-39573

ELSA-2026-39573: yggdrasil security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-38995

ELSA-2026-38995: go-toolset:ol8 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
rocky логотип
RLSA-2026:34359

Important: opentelemetry-collector security update

2 месяца назад
rocky логотип
RLSA-2026:34357

Important: opentelemetry-collector security update

2 месяца назад
ubuntu логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-27145

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-27145

Inefficient candidate hostname parsing in crypto/x509

1%
Низкий
3 месяца назад
debian логотип
CVE-2026-27145

*x509.Certificate).VerifyHostname previously called matchHostnames in ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 8.2
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

CVSS3: 9.6
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

CVSS3: 10
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...

CVSS3: 9.6
1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:46394

Important: go-fdo-client security update

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4279-q6mj-392r

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

CVSS3: 6.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу