Vendor Intelligence

go

98 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-52798 · CVSS 8.9

Gogs has Stored XSS in `.ipynb` Preview

View CVE report →
CVE-2026-41053 · CVSS 8.8

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

View CVE report →
CVE-2026-44829 · CVSS 8.8

Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename

View CVE report →
CVE-2026-44938 · CVSS 8.8

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

View CVE report →
CVE-2026-46612 · CVSS 8.8

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

View CVE report →
CVE-2026-47125 · CVSS 8.8

Arcane: Missing admin authorization on global variables endpoint

View CVE report →
CVE-2026-49258 · CVSS 8.8

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

View CVE report →
CVE-2026-52800 · CVSS 8.8

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

View CVE report →
CVE-2026-28737 · CVSS 8.7

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

View CVE report →
CVE-2026-44543 · CVSS 8.7

Local Path Provisioner Vulnerable to HelperPod Template Injection

View CVE report →
CVE-2026-49478 · CVSS 8.7

Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage

View CVE report →
CVE-2026-52805 · CVSS 8.7

Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft

View CVE report →
CVE-2026-55429 · CVSS 8.7

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

View CVE report →
CVE-2025-71261 · CVSS 8.6

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

View CVE report →
CVE-2026-39383 · CVSS 8.6

Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL

View CVE report →
CVE-2026-42595 · CVSS 8.6

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

View CVE report →
CVE-2026-44697 · CVSS 8.6

Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload

View CVE report →
CVE-2026-45298 · CVSS 8.6

Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)

View CVE report →
CVE-2026-54628 · CVSS 8.6

Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode

View CVE report →
CVE-2026-26231 · CVSS 8.5

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

View CVE report →
CVE-2026-44850 · CVSS 8.5

Portainer has a bind-mount restriction bypass via HostConfig.Mounts

View CVE report →
CVE-2026-46717 · CVSS 8.5

Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification

View CVE report →
CVE-2026-47201 · CVSS 8.5

authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user

View CVE report →
CVE-2026-49824 · CVSS 8.5

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

View CVE report →
CVE-2026-52797 · CVSS 8.5

Gogs: Overwriting critical files results in a denial of service

View CVE report →
CVE-2026-45730 · CVSS 8.3

Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project

View CVE report →
CVE-2026-54174 · CVSS 8.3

melange: Incomplete package integrity verification allows data section substitution

View CVE report →
CVE-2026-55427 · CVSS 8.3

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

View CVE report →
CVE-2026-40893 · CVSS 8.2

Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move

View CVE report →
CVE-2026-42083 · CVSS 8.2

Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI

View CVE report →
CVE-2026-44328 · CVSS 8.2

free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating

View CVE report →
CVE-2026-45089 · CVSS 8.2

Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option

View CVE report →
CVE-2026-46415 · CVSS 8.2

Caddy Defender trusted proxy client IP bypass

View CVE report →
CVE-2026-48126 · CVSS 8.2

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

View CVE report →
CVE-2026-48788 · CVSS 8.2

Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing

View CVE report →
CVE-2026-49998 · CVSS 8.2

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

View CVE report →
CVE-2026-55428 · CVSS 8.2

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

View CVE report →
CVE-2026-55667 · CVSS 8.2

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

View CVE report →
CVE-2026-22555 · CVSS 8.1

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

View CVE report →
CVE-2026-24791 · CVSS 8.1

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

View CVE report →
CVE-2026-28699 · CVSS 8.1

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

View CVE report →
CVE-2026-28744 · CVSS 8.1

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

View CVE report →
CVE-2026-42221 · CVSS 8.1

Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim

View CVE report →
CVE-2026-42222 · CVSS 8.1

Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover

View CVE report →
CVE-2026-42296 · CVSS 8.1

Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure

View CVE report →
CVE-2026-42602 · CVSS 8.1

opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay

View CVE report →
CVE-2026-44454 · CVSS 8.1

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

View CVE report →
CVE-2026-44882 · CVSS 8.1

Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

View CVE report →
CVE-2026-44973 · CVSS 8.1

go-billy has path traversal vulnerabilities

View CVE report →
CVE-2026-45062 · CVSS 8.1

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

View CVE report →
CVE-2026-45135 · CVSS 8.1

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

View CVE report →
CVE-2026-49340 · CVSS 8.1

gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

View CVE report →
CVE-2026-50138 · CVSS 8.1

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

View CVE report →
CVE-2026-52801 · CVSS 8.1

Gogs has the ability to import local repositories via Mirror Settings

View CVE report →
CVE-2026-52845 · CVSS 8.1

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

View CVE report →
CVE-2026-61699 · CVSS 8.1

nebula-mesh: Certificate revocation is never enforced at the mesh

View CVE report →
CVE-2026-62685 · CVSS 8.1

File Browser: Colliding username normalization gives two users the same home directory

View CVE report →
CVE-2026-11401 · CVSS 8

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

View CVE report →
CVE-2026-52833 · CVSS 8

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

View CVE report →
CVE-2026-45152 · CVSS 7.8

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

View CVE report →
CVE-2026-42283 · CVSS 7.7

DevSpace UI Server WebSocket CheckOrigin does not validate source

View CVE report →
CVE-2026-49821 · CVSS 7.7

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

View CVE report →
CVE-2026-49823 · CVSS 7.7

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

View CVE report →
CVE-2026-53999 · CVSS 7.7

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

View CVE report →
CVE-2026-55431 · CVSS 7.7

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

View CVE report →
CVE-2026-24899 · CVSS 7.5

Fleet Windows MDM Azure AD JWT Authentication Bypass

View CVE report →
CVE-2026-33190 · CVSS 7.5

CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC

View CVE report →
CVE-2026-33489 · CVSS 7.5

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

View CVE report →
CVE-2026-42295 · CVSS 7.5

Argo vulnerable to exposure of artifact repository credentials

View CVE report →
CVE-2026-42339 · CVSS 7.5

QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0

View CVE report →
CVE-2026-42575 · CVSS 7.5

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)

View CVE report →
CVE-2026-44316 · CVSS 7.5

free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference

View CVE report →
CVE-2026-44321 · CVSS 7.5

free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)

View CVE report →
CVE-2026-44322 · CVSS 7.5

free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference

View CVE report →
CVE-2026-44325 · CVSS 7.5

free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types

View CVE report →
CVE-2026-44594 · CVSS 7.5

esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files

View CVE report →
CVE-2026-45678 · CVSS 7.5

OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

View CVE report →
CVE-2026-45685 · CVSS 7.5

OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages

View CVE report →
CVE-2026-45741 · CVSS 7.5

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

View CVE report →
CVE-2026-46377 · CVSS 7.5

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

View CVE report →
CVE-2026-46378 · CVSS 7.5

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

View CVE report →
CVE-2026-46680 · CVSS 7.5

containerd user ID handling bypass allows runAsNonRoot evasion

View CVE report →
CVE-2026-47243 · CVSS 7.5

Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

View CVE report →
CVE-2026-47726 · CVSS 7.5

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

View CVE report →
CVE-2026-48020 · CVSS 7.5

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

View CVE report →
CVE-2026-48089 · CVSS 7.5

DevGuard has improper authorization on public assets

View CVE report →
CVE-2026-48491 · CVSS 7.5

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

View CVE report →
CVE-2026-50141 · CVSS 7.5

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

View CVE report →
CVE-2026-50151 · CVSS 7.5

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

View CVE report →
CVE-2026-52807 · CVSS 7.5

Gogs has DOM-based XSS via Milestone Name on New Issue Page

View CVE report →
CVE-2026-52844 · CVSS 7.5

Caddy: Windows `file_server` path authorization bypass via encoded backslash

View CVE report →
CVE-2026-53622 · CVSS 7.5

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

View CVE report →
CVE-2026-54090 · CVSS 7.5

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

View CVE report →
CVE-2026-61549 · CVSS 7.5

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

View CVE report →
CVE-2026-6970 · CVSS 7.5

authd: Primary group ID is incorrectly set to value of UID

View CVE report →
CVE-2026-45738 · CVSS 7.3

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

View CVE report →
CVE-2026-49339 · CVSS 7.1

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

View CVE report →
CVE-2026-50163 · CVSS 7.1

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

View CVE report →