Vulnerabilidades em Go standard library

121 resultados
Análise Vexday

Com 111 CVEs catalogadas e nenhuma confirmada em exploração ativa segundo o CISA KEV, a Go standard library apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina riscos relevantes. O score EPSS de 0,9197 associado a CVE-2023-45288 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção prioritária. O tipo de falha mais frequente é CWE-94 (injeção de código), e a existência de 2 CVEs com prova de conceito pública amplia a superfície de risco para equipes que ainda não aplicaram as correções correspondentes. As 18 vulnerabilidades surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo, dado o ritmo recente de descobertas.

CVE-2026-42507MEDIUMArbitrary inputs are included in errors without any escaping in net/textprotoEPSS 0.4%CVE-2025-47907HIGHIncorrect results returned from Rows.Scan in database/sqlEPSS 0.4%CVE-2025-58188HIGHPanic when validating certificates with DSA public keys in crypto/x509EPSS 0.4%CVE-2026-32281HIGHInefficient policy validation in crypto/x509EPSS 0.4%CVE-2026-27138MEDIUMPanic in name constraint checking for malformed certificates in crypto/x509EPSS 0.4%CVE-2026-33810HIGHCase-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509EPSS 0.3%CVE-2025-47910MEDIUMCrossOriginProtection insecure bypass patterns not limited to exact matches in net/httpEPSS 0.3%CVE-2026-27142MEDIUMURLs in meta content attribute actions are not escaped in html/templateEPSS 0.3%CVE-2026-39823MEDIUMBypass of meta content URL escaping causes XSS in html/templateEPSS 0.3%CVE-2025-0913MEDIUMInconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscallEPSS 0.3%CVE-2026-56858MEDIUMFix Javascript regexp context tracking in html/templateEPSS 0.3%CVE-2026-32282MEDIUMTOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unixEPSS 0.3%CVE-2026-32289MEDIUMJsBraceDepth Context Tracking Bugs (XSS) in html/templateEPSS 0.3%CVE-2026-32288MEDIUMUnbounded allocation for old GNU sparse in archive/tarEPSS 0.3%CVE-2025-22866MEDIUMTiming sidechannel for P-256 on ppc64le in crypto/internal/nistecEPSS 0.3%CVE-2025-61730MEDIUMHandshake messages may be processed at the incorrect encryption level in crypto/tlsEPSS 0.3%CVE-2025-61727MEDIUMImproper application of excluded DNS name constraints when verifying wildcard names in crypto/x509EPSS 0.3%CVE-2025-22873LOWImproper access to parent directory of root in osEPSS 0.2%CVE-2026-39822HIGHRoot escape via symlink plus trailing slash in osEPSS 0.2%CVE-2024-8244LOWWalk/WalkDir in path/filepath susceptible to symlink raceEPSS 0.2%