Количество 45
Количество 45
RLSA-2026:29981
Moderate: golang security, bug fix, and enhancement update
openSUSE-SU-2026:20977-1
Security update for go1.25
openSUSE-SU-2026:20976-1
Security update for go1.26
SUSE-SU-2026:2327-1
Security update for go1.26
SUSE-SU-2026:2326-1
Security update for go1.25
SUSE-SU-2026:3102-1
Security update for go1.26-openssl
SUSE-SU-2026:3047-1
Security update for go1.26-openssl
SUSE-SU-2026:3151-1
Security update for go1.25-openssl
SUSE-SU-2026:3046-1
Security update for go1.25-openssl
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.
CVE-2026-42507
Arbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-42507
When returning errors, functions in the net/textproto package would in ...
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
CVE-2026-27145
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-27145
*x509.Certificate).VerifyHostname previously called matchHostnames in ...
openSUSE-SU-2026:21254-1
Security update for go1.26-openssl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:29981 Moderate: golang security, bug fix, and enhancement update | около 1 месяца назад | |||
openSUSE-SU-2026:20977-1 Security update for go1.25 | около 1 месяца назад | |||
openSUSE-SU-2026:20976-1 Security update for go1.26 | около 1 месяца назад | |||
SUSE-SU-2026:2327-1 Security update for go1.26 | около 2 месяцев назад | |||
SUSE-SU-2026:2326-1 Security update for go1.25 | около 2 месяцев назад | |||
SUSE-SU-2026:3102-1 Security update for go1.26-openssl | 14 дней назад | |||
SUSE-SU-2026:3047-1 Security update for go1.26-openssl | 16 дней назад | |||
SUSE-SU-2026:3151-1 Security update for go1.25-openssl | 10 дней назад | |||
SUSE-SU-2026:3046-1 Security update for go1.25-openssl | 16 дней назад | |||
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-42507 When returning errors, functions in the net/textproto package would in ... | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-27145 *x509.Certificate).VerifyHostname previously called matchHostnames in ... | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21254-1 Security update for go1.26-openssl | 23 дня назад |
Уязвимостей на страницу