from 0
CRITICAL9.8CVE-2026-27143Missing bound checks can lead to memory corruption in safe Go in cmd/compile from 0
CRITICAL9.8Output of "go env" does not sanitize values in cmd/go
from 0
CRITICAL9.8Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
from 0
CRITICAL9.8Code injection via go command with cgo in cmd/go
from 0
CRITICAL9.8Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
from 0
CRITICAL9.8Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
from 0
CRITICAL9.8Improper handling of JavaScript whitespace in html/template
from 0
CRITICAL9.8Backticks not treated as string delimiters in html/template
from 0, < 1.19.8-2
CRITICAL9.1Request smuggling due to acceptance of invalid chunked data in net/http
from 0
HIGH8.8Code execution vulnerability in SWIG code generation in cmd/go
from 0
HIGH8.6Potential code smuggling via doc comments in cmd/cgo
from 0
HIGH8.6Unexpected command execution in untrusted VCS repositories in cmd/go
from 0
HIGH8.1Arbitrary code execution during build via line directives in cmd/go
from 0
HIGH7.8Arbitrary file write using cgo pkg-config directive in cmd/go
from 0
HIGH7.8Unsafe behavior in setuid/setgid binaries in runtime
from 0
HIGH7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
from 0
HIGH7.5Crash when handling long CNAME response in net
from 0
HIGH7.5Malicious module proxy can bypass checksum database in cmd/go
from 0
HIGH7.5Quadratic string concatenation in consumePhrase in net/mail
from 0
HIGH7.5Quadratic string concatentation in consumeComment in net/mail
from 0
HIGH7.5Inefficient policy validation in crypto/x509
from 0
HIGH7.5Unexpected work during chain building in crypto/x509
from 0
HIGH7.5Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
from 0
HIGH7.5Memory exhaustion in query parameter parsing in net/url
from 0
HIGH7.5Excessive resource consumption when printing error string for host certificate validation in crypto/x509
from 0
HIGH7.5Panic when validating certificates with DSA public keys in crypto/x509
from 0
HIGH7.5Quadratic complexity when parsing some invalid inputs in encoding/pem
from 0
HIGH7.5Quadratic complexity when checking name constraints in crypto/x509
from 0
HIGH7.5Excessive CPU consumption in ParseAddress in net/mail
from 0
HIGH7.5Stack exhaustion in Parse in go/build/constraint
from 0
HIGH7.5Stack exhaustion in Decoder.Decode in encoding/gob
from 0
HIGH7.5Denial of service due to improper 100-continue handling in net/http
from 0
HIGH7.5Comments in display names are incorrectly handled in net/mail
from 0
HIGH7.5Command 'go get' may unexpectedly fallback to insecure git in cmd/go
from 0
HIGH7.5Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel
from 0
HIGH7.5Insecure parsing of Windows paths with a \??\ prefix in path/filepath
from 0
HIGH7.5HTTP/2 rapid reset can cause excessive work in net/http
from 0
HIGH7.5Infinite loop in parsing in go/scanner
from 0, < 1.19.8-2
HIGH7.5Excessive resource consumption in net/http, net/textproto and mime/multipart
from 0, < 1.19.8-2
HIGH7.5Excessive memory allocation in net/http and net/textproto
from 0, < 1.19.8-2
HIGH7.5Excessive resource consumption in mime/multipart
from 0, < 1.19.6-2
HIGH7.5Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
from 0, < 1.19.6-2
HIGH7.5Panic on large handshake records in crypto/tls
from 0, < 1.19.6-2
HIGH7.5Path traversal on Windows in path/filepath
from 0, < 1.19.6-2
HIGH7.5Restricted file access on Windows in os and net/http
from 0, < 1.19.4-1
HIGH7.5Unsanitized NUL in environment variables on Windows in syscall and os/exec
from 0, < 1.19.3-1
HIGH7.5Incorrect sanitization of forwarded query parameters in net/http/httputil
from 0, < 1.19.2-1
HIGH7.5Memory exhaustion when compiling regular expressions in regexp/syntax
from 0, < 1.19.2-1
HIGH7.5Unbounded memory consumption when reading headers in archive/tar
from 0, < 1.19.2-1
HIGH7.5Failure to strip relative path components in net/url
from 0, < 1.19.1-1
HIGH7.5Denial of service in net/http and golang.org/x/net/http2
from 0, < 1.19.1-1
HIGH7.5Panic when decoding Float and Rat types in math/big
from 0, < 1.19-1
HIGH7.5Stack exhaustion in Glob on certain paths in io/fs
from 0, < 1.19~rc2-1
HIGH7.5Stack exhaustion when decoding certain messages in encoding/gob
from 0, < 1.19~rc2-1
HIGH7.5Stack exhaustion when reading certain archives in compress/gzip
from 0, < 1.19~rc2-1
HIGH7.5Stack exhaustion when unmarshaling certain documents in encoding/xml
from 0, < 1.19~rc2-1
HIGH7.5Stack exhaustion on crafted paths in path/filepath
from 0, < 1.19~rc2-1
HIGH7.3Improper handling of empty HTML attributes in html/template
from 0
HIGH7.3Improper sanitization of CSS values in html/template
from 0
HIGH7.1Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
from 0
HIGH7.0Unexpected code execution when invoking toolchain in cmd/go
from 0
HIGH7.0Incorrect results returned from Rows.Scan in database/sql
from 0
MEDIUM6.8Sensitive headers not cleared on cross-origin redirect in net/http
from 0
MEDIUM6.5Inefficient candidate hostname parsing in crypto/x509
from 0
MEDIUM6.5Excessive CPU consumption when building archive index in archive/zip
from 0
MEDIUM6.5Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509
from 0
MEDIUM6.5Unexpected paths returned from LookPath in os/exec
from 0
MEDIUM6.5Memory exhaustion in multipart form parsing in net/textproto and net/http
from 0
MEDIUM6.5Insufficient sanitization of Host header in net/http
from 0
MEDIUM6.5Exposure of client IP addresses in net/http
from 0, < 1.19~rc1-1
MEDIUM6.5Improper sanitization of Transfer-Encoding headers in net/http
from 0, < 1.19~rc1-1
MEDIUM6.4TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
from 0
MEDIUM6.1Bypass of meta content URL escaping causes XSS in html/template
from 0
MEDIUM6.1Escaper bypass leads to XSS in html/template
from 0
MEDIUM6.1JsBraceDepth Context Tracking Bugs (XSS) in html/template
from 0
MEDIUM6.1URLs in meta content attribute actions are not escaped in html/template
from 0
MEDIUM6.1Sensitive headers incorrectly sent after cross-domain redirect in net/http
from 0
MEDIUM6.1Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509
from 0
MEDIUM6.1Improper handling of special tags within script contexts in html/template
from 0
MEDIUM6.1Improper handling of HTML-like comments in script contexts in html/template
from 0
MEDIUM5.9Invoking "go tool pack" does not sanitize output paths in cmd/go
from 0
MEDIUM5.9Verify panics on certificates with an unknown public key algorithm in crypto/x509
from 0
MEDIUM5.5Unbounded allocation for old GNU sparse in archive/tar
from 0
MEDIUM5.5Mishandling of corrupt central directory record in archive/zip
from 0
MEDIUM5.5Stack exhaustion due to deeply nested types in go/parser
from 0, < 1.19~rc2-1
MEDIUM5.4Errors returned from JSON marshaling may break template escaping in html/template
from 0
MEDIUM5.3Arbitrary inputs are included in errors without any escaping in net/textproto
from 0
MEDIUM5.3Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
from 0
MEDIUM5.3ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
from 0
MEDIUM5.3Handshake messages may be processed at the incorrect encryption level in crypto/tls
from 0
MEDIUM5.3Excessive CPU consumption in Reader.ReadResponse in net/textproto
from 0
MEDIUM5.3Lack of limit when parsing cookies can cause memory exhaustion in net/http
from 0
MEDIUM5.3Parsing DER payload can cause memory exhaustion in encoding/asn1
from 0
MEDIUM5.3Insufficient validation of bracketed IPv6 hostnames in net/url
from 0
MEDIUM5.3ALPN negotiation error contains attacker controlled information in crypto/tls
from 0
MEDIUM5.3HTTP/2 CONTINUATION flood in net/http
from 0
MEDIUM5.3Denial of service via chunk extensions in net/http
from 0
MEDIUM5.3Incorrect detection of reserved device names on Windows in path/filepath
from 0
MEDIUM5.3Large RSA keys can cause high CPU usage in crypto/tls
from 0
MEDIUM5.3Incorrect calculation on P256 curves in crypto/internal/nistec
from 0, < 1.19.8-2
MEDIUM5.3Excessive memory growth in net/http and golang.org/x/net/http2
from 0, < 1.19.4-1
MEDIUM4.4HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
from 0
MEDIUM4.3Unbounded allocation when parsing GNU sparse map in archive/tar
from 0
MEDIUM4.3Stack exhaustion in all Parse functions in go/parser
from 0
MEDIUM4.3Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
from 0
MEDIUM4.0Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
from 0
LOW3.7The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TO…
from 0
LOW2.5FileInfo can escape from a Root in os
from 0