Vulnerabilidades em Go standard library

121 resultados
Análise Vexday

Com 111 CVEs catalogadas e nenhuma confirmada em exploração ativa segundo o CISA KEV, a Go standard library apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina riscos relevantes. O score EPSS de 0,9197 associado a CVE-2023-45288 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção prioritária. O tipo de falha mais frequente é CWE-94 (injeção de código), e a existência de 2 CVEs com prova de conceito pública amplia a superfície de risco para equipes que ainda não aplicaram as correções correspondentes. As 18 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo, dado o ritmo recente de descobertas.

CVE-2025-68121CRITICALUnexpected session resumption in crypto/tlsEPSS 0.8%CVE-2026-25679HIGHIncorrect parsing of IPv6 host literals in net/urlEPSS 0.7%CVE-2026-39821CRITICALInvoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaEPSS 0.7%CVE-2025-61728MEDIUMExcessive CPU consumption when building archive index in archive/zipEPSS 0.7%CVE-2024-45336MEDIUMSensitive headers incorrectly sent after cross-domain redirect in net/httpEPSS 0.7%CVE-2024-24783MEDIUMVerify panics on certificates with an unknown public key algorithm in crypto/x509EPSS 0.7%CVE-2025-4673MEDIUMSensitive headers not cleared on cross-origin redirect in net/httpEPSS 0.7%CVE-2026-32283HIGHUnauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tlsEPSS 0.6%CVE-2022-30580HIGHEmpty Cmd.Path can trigger unintended binary in os/exec on WindowsEPSS 0.6%CVE-2025-61723HIGHQuadratic complexity when parsing some invalid inputs in encoding/pemEPSS 0.6%CVE-2026-32280HIGHUnexpected work during chain building in crypto/x509EPSS 0.6%CVE-2025-22865HIGHParsePKCS1PrivateKey panic with partial keys in crypto/x509EPSS 0.6%CVE-2026-27137HIGHIncorrect enforcement of email constraints in crypto/x509EPSS 0.6%CVE-2025-61725HIGHExcessive CPU consumption in ParseAddress in net/mailEPSS 0.6%CVE-2026-27145MEDIUMInefficient candidate hostname parsing in crypto/x509EPSS 0.6%CVE-2026-39836HIGHPanic in Dial and LookupPort when handling NUL byte on Windows in netEPSS 0.6%CVE-2026-56853HIGHApply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/httpEPSS 0.6%CVE-2026-33818HIGHEnforce maximum recursion depth in encoding/asn1EPSS 0.6%CVE-2026-56859HIGHAdd recursion depth guard during decode in encoding/xmlEPSS 0.6%CVE-2026-56862HIGHLimit handshake messages we are willing to accept post-handshake in crypto/tlsEPSS 0.6%