Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

github логотип

GHSA-m3xc-h892-ggx6

3 месяца назад

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-44740

около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-44740

около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44740

около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-44740

около 2 месяцев назад

Billy is an interface filesystem abstraction for Go. Prior to versions ...

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2026:46391

3 дня назад

Important: grafana security, bug fix, and enhancement update

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21072-1

около 1 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21079-1

около 1 месяца назад

Security update for amazon-ssm-agent

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20956-1

около 2 месяцев назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2468-1

около 1 месяца назад

Security update for amazon-ssm-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2467-1

около 1 месяца назад

Security update for amazon-ssm-agent

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21251-1

24 дня назад

Security update for alloy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2824-1

22 дня назад

Security update for alloy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21436-1

8 дней назад

Security update for rclone

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3056-1

16 дней назад

Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m3xc-h892-ggx6

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-44740

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-44740

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-44740

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-44740

Billy is an interface filesystem abstraction for Go. Prior to versions ...

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:46391

Important: grafana security, bug fix, and enhancement update

0%
Низкий
3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21072-1

Security update for trivy

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21079-1

Security update for amazon-ssm-agent

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20956-1

Security update for trivy

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2468-1

Security update for amazon-ssm-agent

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2467-1

Security update for amazon-ssm-agent

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21251-1

Security update for alloy

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:2824-1

Security update for alloy

22 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21436-1

Security update for rclone

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:3056-1

Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider-null, terraform-provider-random, terraform-provider-tls

16 дней назад

Уязвимостей на страницу