Vulnerabilidades em Go standard library

121 resultados
Análise Vexday

Com 111 CVEs catalogadas e nenhuma confirmada em exploração ativa segundo o CISA KEV, a Go standard library apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina riscos relevantes. O score EPSS de 0,9197 associado a CVE-2023-45288 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção prioritária. O tipo de falha mais frequente é CWE-94 (injeção de código), e a existência de 2 CVEs com prova de conceito pública amplia a superfície de risco para equipes que ainda não aplicaram as correções correspondentes. As 18 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo, dado o ritmo recente de descobertas.

CVE-2023-45289MEDIUMIncorrect forwarding of sensitive headers and cookies on HTTP redirect in net/httpEPSS 1.1%CVE-2022-30629LOWSession tickets lack random ticket_age_add in crypto/tlsEPSS 1.1%CVE-2024-24784HIGHComments in display names are incorrectly handled in net/mailEPSS 1.1%CVE-2024-34158HIGHStack exhaustion in Parse in go/build/constraintEPSS 1.0%CVE-2023-29400HIGHImproper handling of empty HTML attributes in html/templateEPSS 1.0%CVE-2023-24539HIGHImproper sanitization of CSS values in html/templateEPSS 1.0%CVE-2024-24788MEDIUMMalformed DNS message can cause infinite loop in netEPSS 1.0%CVE-2023-39318Improper handling of HTML-like comments in script contexts in html/templateEPSS 0.9%CVE-2023-39319Improper handling of special tags within script contexts in html/templateEPSS 0.9%CVE-2022-1962MEDIUMStack exhaustion due to deeply nested types in go/parserEPSS 0.9%CVE-2023-45284MEDIUMIncorrect detection of reserved device names on Windows in path/filepathEPSS 0.9%CVE-2024-34155MEDIUMStack exhaustion in all Parse functions in go/parserEPSS 0.8%CVE-2022-41716MEDIUMUnsanitized NUL in environment variables on Windows in syscall and os/execEPSS 0.8%CVE-2023-24532Incorrect calculation on P256 curves in crypto/internal/nistecEPSS 0.8%CVE-2026-33811HIGHCrash when handling long CNAME response in netEPSS 0.8%CVE-2025-22871CRITICALRequest smuggling due to acceptance of invalid chunked data in net/httpEPSS 0.8%CVE-2026-42499HIGHQuadratic string concatenation in consumePhrase in net/mailEPSS 0.8%CVE-2024-24785MEDIUMErrors returned from JSON marshaling may break template escaping in html/templateEPSS 0.8%CVE-2026-39820HIGHQuadratic string concatentation in consumeComment in net/mailEPSS 0.8%CVE-2026-33814HIGHInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/netEPSS 0.8%