Package impact

golang Go / stdlib

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2025-68121 critical 10.0 10.0 9d ago Important: osbuild-composer security update rockylinuxredhatdebiansuse+2
CVE-2015-5740 critical 9.8 9.8 9y ago Request smuggling due to improper header parsing in net/http redhatfedoragolang
CVE-2015-5739 critical 9.8 9.8 9y ago Request smuggling due to improper header parsing in net/http redhatfedoragolang
CVE-2023-29403 critical 9.5 3y ago Critical: go-toolset and golang security update redhatdebianrockylinuxgolang
CVE-2025-22871 critical 9.1 9.1 10mo ago Moderate: weldr-client security update redhatrockylinuxdebiansuse+2
CVE-2016-5386 high 8.1 8.1 10y ago Improper input validation in net/http and net/http/cgi fedoraredhatgolang
CVE-2026-27137 high 8.0 9d ago Important: golang security update redhatdebiansusegolang
CVE-2026-33810 high 8.0 9d ago Important: opentelemetry-collector security update redhatdebiansusegolang
CVE-2026-32281 high 8.0 9d ago Important: opentelemetry-collector security update redhatdebiansusegolang+1
CVE-2025-61726 high 8.0 9d ago Important: image-builder security update rockylinuxredhatdebiansuse+2
CVE-2026-25679 high 8.0 23d ago Important: golang security update rockylinuxredhatdebiansuse+2
CVE-2026-32280 high 8.0 1mo ago Important: opentelemetry-collector security update redhatdebiansusegolang+1
CVE-2026-32282 high 8.0 1mo ago Important: opentelemetry-collector security update redhatdebiansusegolang+1
CVE-2026-32283 high 8.0 1mo ago Important: opentelemetry-collector security update redhatdebiansusegolang+1
CVE-2025-61728 high 8.0 3mo ago Important: osbuild-composer security update rockylinuxredhatdebiansuse+2
CVE-2025-61729 high 8.0 4mo ago Important: osbuild-composer security update rockylinuxredhatdebiansuse+2
CVE-2025-58183 high 8.0 6mo ago Important: buildah security update rockylinuxredhatdebiansuse+1
CVE-2025-47907 high 8.0 9mo ago Important: podman security update redhatdebiansusegolang+1
CVE-2025-22866 high 8.0 1y ago Important: delve and golang security update redhatdebiansuserockylinux+1
CVE-2024-34156 high 8.0 2y ago Important: golang security update redhatrockylinuxdebiansuse+1
CVE-2024-34158 high 8.0 2y ago Important: golang security update redhatrockylinuxdebiansuse+1
CVE-2024-34155 high 8.0 2y ago Important: golang security update redhatrockylinuxdebiansuse+1
CVE-2024-24789 high 8.0 2y ago Important: container-tools:rhel8 security update redhatrockylinuxdebiansuse+1
CVE-2023-45290 high 8.0 2y ago Important: git-lfs security update redhatrockylinuxsusedebian+1
CVE-2023-45289 high 8.0 2y ago Important: git-lfs security update redhatrockylinuxsusedebian+1
CVE-2024-24783 high 8.0 2y ago Important: golang security update redhatrockylinuxdebiansuse+1
CVE-2024-24784 high 8.0 2y ago Important: golang security update redhatrockylinuxdebiansuse+1
CVE-2024-24785 high 8.0 2y ago Important: golang security update rockylinuxredhatdebiansuse+1
CVE-2023-45288 high 8.0 2y ago Important: git-lfs security update redhatrockylinuxsusedebian+1
CVE-2023-39325 high 8.0 3y ago Important: go-toolset and golang security and bug fix update redhatrockylinuxsusedebian+1
CVE-2023-24532 high 8.0 3y ago The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not … redhatsusedebiangolang
CVE-2022-29526 high 8.0 4y ago Important: go-toolset and golang security and bug fix update redhatsuserockylinuxdebian+1
CVE-2022-28131 high 8.0 4y ago Important: grafana security, bug fix, and enhancement update rockylinuxredhatsusedebian+1
CVE-2022-24921 high 8.0 4y ago Important: go-toolset and golang security and bug fix update redhatsuserockylinuxdebian+1
CVE-2022-24675 high 8.0 4y ago Important: go-toolset and golang security and bug fix update redhatsuserockylinuxgolang
CVE-2022-1962 high 8.0 4y ago Important: grafana security, bug fix, and enhancement update rockylinuxredhatsusedebian+1
CVE-2022-28327 high 8.0 4y ago Important: go-toolset and golang security and bug fix update redhatsuserockylinuxgolang
CVE-2022-30630 high 8.0 4y ago Important: grafana security, bug fix, and enhancement update rockylinuxredhatsusedebian+1
CVE-2022-30635 high 8.0 4y ago Important: grafana security, bug fix, and enhancement update rockylinuxredhatsusedebian+1
CVE-2018-16875 high 8.0 4y ago Denial of service in chain verification in crypto/x509 archsusegolang
CVE-2019-9514 high 8.0 4y ago Important: nodejs:10 security update archsusedebianrockylinux+1
CVE-2019-9512 high 8.0 4y ago Important: container-tools:rhel8 security and bug fix update archsusedebianrockylinux+1
CVE-2019-16276 high 8.0 4y ago Request smuggling due to accepting invalid headers in net/http via net/textproto archsusegolang
CVE-2021-44717 high 8.0 4y ago Important: go-toolset:rhel8 security and bug fix update archdebianrockylinuxgolang
CVE-2021-44716 high 8.0 5y ago Important: grafana security update archsusedebianrockylinux+1
CVE-2020-28362 high 8.0 5y ago Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. archsusedebiangolang
CVE-2016-3958 high 7.8 7.8 10y ago Privilege escalation on Windows via malicious DLL in syscall golang
CVE-2026-42499 high 7.5 7.5 20d ago Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. debiansusegolanggcp
CVE-2026-39836 high 7.5 7.5 20d ago The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). debiansusegolanggcp
CVE-2026-39820 high 7.5 7.5 20d ago Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. debiansusegolanggcp
CVE-2026-33814 high 7.5 7.5 20d ago When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. debiansusegolanggcp
CVE-2026-33811 high 7.5 7.5 20d ago When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. debiansusegolang
CVE-2017-1000098 high 7.5 7.5 9y ago Denial of service when parsing large forms in mime/multipart archgolang
CVE-2017-1000097 high 7.5 7.5 9y ago Mishandled trust preferences for root certificates on Darwin in crypto/x509 golang
CVE-2016-3959 high 7.5 7.5 10y ago Denial of service due to unchecked parameters in crypto/dsa susefedoragolang
CVE-2015-8618 high 7.5 7.5 11y ago Incorrect calculation affecting RSA computations in math/big susegolang
CVE-2025-22873 low 2.5 4mo ago It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape o… archdebiansusegolang
CVE-2021-27919 low 2.5 5y ago archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any fi… archsusedebiangolang