Vulnerabilidades em go
5 resultadosAnálise Vexday
Go apresenta um volume mínimo de vulnerabilidades conhecidas (1 CVE), sem registros de exploração ativa em ambiente de produção. A vulnerabilidade foi divulgada recentemente (últimos 90 dias), mas não atinge nível crítico, representando um risco baixo para adotantes da linguagem.
CVE-2017-3204—The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in EPSS 3.2%CVE-2026-78427MEDIUMAdmission Control Bypass via Hardcoded Sidecar Image ExemptionEPSS 0.4%CVE-2026-78425HIGHSAML Audience Confusion Allows Cross-SP AuthenticationEPSS 0.3%CVE-2026-78428HIGHFlaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrentlyEPSS 0.2%CVE-2026-78426LOWLogout bypass via alternate JWT spellingEPSS 0.1%