Vendor Intelligence
go
98 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.
CVE-2026-52798 · CVSS 8.9
Gogs has Stored XSS in `.ipynb` Preview
View CVE report →
CVE-2026-41053 · CVSS 8.8
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
View CVE report →
CVE-2026-44829 · CVSS 8.8
Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename
View CVE report →
CVE-2026-44938 · CVSS 8.8
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
View CVE report →
CVE-2026-46612 · CVSS 8.8
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
View CVE report →
CVE-2026-47125 · CVSS 8.8
Arcane: Missing admin authorization on global variables endpoint
View CVE report →
CVE-2026-49258 · CVSS 8.8
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
View CVE report →
CVE-2026-52800 · CVSS 8.8
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
View CVE report →
CVE-2026-28737 · CVSS 8.7
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
View CVE report →
CVE-2026-44543 · CVSS 8.7
Local Path Provisioner Vulnerable to HelperPod Template Injection
View CVE report →
CVE-2026-49478 · CVSS 8.7
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
View CVE report →
CVE-2026-52805 · CVSS 8.7
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
View CVE report →
CVE-2026-55429 · CVSS 8.7
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
View CVE report →
CVE-2025-71261 · CVSS 8.6
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
View CVE report →
CVE-2026-39383 · CVSS 8.6
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
View CVE report →
CVE-2026-42595 · CVSS 8.6
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
View CVE report →
CVE-2026-44697 · CVSS 8.6
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
View CVE report →
CVE-2026-45298 · CVSS 8.6
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
View CVE report →
CVE-2026-54628 · CVSS 8.6
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
View CVE report →
CVE-2026-26231 · CVSS 8.5
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
View CVE report →
CVE-2026-44850 · CVSS 8.5
Portainer has a bind-mount restriction bypass via HostConfig.Mounts
View CVE report →
CVE-2026-46717 · CVSS 8.5
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
View CVE report →
CVE-2026-47201 · CVSS 8.5
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
View CVE report →
CVE-2026-49824 · CVSS 8.5
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
View CVE report →
CVE-2026-52797 · CVSS 8.5
Gogs: Overwriting critical files results in a denial of service
View CVE report →
CVE-2026-45730 · CVSS 8.3
Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project
View CVE report →
CVE-2026-54174 · CVSS 8.3
melange: Incomplete package integrity verification allows data section substitution
View CVE report →
CVE-2026-55427 · CVSS 8.3
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
View CVE report →
CVE-2026-40893 · CVSS 8.2
Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move
View CVE report →
CVE-2026-42083 · CVSS 8.2
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
View CVE report →
CVE-2026-44328 · CVSS 8.2
free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
View CVE report →
CVE-2026-45089 · CVSS 8.2
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
View CVE report →
CVE-2026-46415 · CVSS 8.2
Caddy Defender trusted proxy client IP bypass
View CVE report →
CVE-2026-48126 · CVSS 8.2
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
View CVE report →
CVE-2026-48788 · CVSS 8.2
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
View CVE report →
CVE-2026-49998 · CVSS 8.2
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
View CVE report →
CVE-2026-55428 · CVSS 8.2
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
View CVE report →
CVE-2026-55667 · CVSS 8.2
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
View CVE report →
CVE-2026-22555 · CVSS 8.1
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
View CVE report →
CVE-2026-24791 · CVSS 8.1
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
View CVE report →
CVE-2026-28699 · CVSS 8.1
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
View CVE report →
CVE-2026-28744 · CVSS 8.1
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
View CVE report →
CVE-2026-42221 · CVSS 8.1
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
View CVE report →
CVE-2026-42222 · CVSS 8.1
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
View CVE report →
CVE-2026-42296 · CVSS 8.1
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
View CVE report →
CVE-2026-42602 · CVSS 8.1
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
View CVE report →
CVE-2026-44454 · CVSS 8.1
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
View CVE report →
CVE-2026-44882 · CVSS 8.1
Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
View CVE report →
CVE-2026-44973 · CVSS 8.1
go-billy has path traversal vulnerabilities
View CVE report →
CVE-2026-45062 · CVSS 8.1
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
View CVE report →
CVE-2026-45135 · CVSS 8.1
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
View CVE report →
CVE-2026-49340 · CVSS 8.1
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
View CVE report →
CVE-2026-50138 · CVSS 8.1
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags
View CVE report →
CVE-2026-52801 · CVSS 8.1
Gogs has the ability to import local repositories via Mirror Settings
View CVE report →
CVE-2026-52845 · CVSS 8.1
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
View CVE report →
CVE-2026-61699 · CVSS 8.1
nebula-mesh: Certificate revocation is never enforced at the mesh
View CVE report →
CVE-2026-62685 · CVSS 8.1
File Browser: Colliding username normalization gives two users the same home directory
View CVE report →
CVE-2026-11401 · CVSS 8
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
View CVE report →
CVE-2026-52833 · CVSS 8
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
View CVE report →
CVE-2026-45152 · CVSS 7.8
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
View CVE report →
CVE-2026-42283 · CVSS 7.7
DevSpace UI Server WebSocket CheckOrigin does not validate source
View CVE report →
CVE-2026-49821 · CVSS 7.7
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
View CVE report →
CVE-2026-49823 · CVSS 7.7
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
View CVE report →
CVE-2026-53999 · CVSS 7.7
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
View CVE report →
CVE-2026-55431 · CVSS 7.7
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
View CVE report →
CVE-2026-24899 · CVSS 7.5
Fleet Windows MDM Azure AD JWT Authentication Bypass
View CVE report →
CVE-2026-33190 · CVSS 7.5
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
View CVE report →
CVE-2026-33489 · CVSS 7.5
CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
View CVE report →
CVE-2026-42295 · CVSS 7.5
Argo vulnerable to exposure of artifact repository credentials
View CVE report →
CVE-2026-42339 · CVSS 7.5
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
View CVE report →
CVE-2026-42575 · CVSS 7.5
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
View CVE report →
CVE-2026-44316 · CVSS 7.5
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
View CVE report →
CVE-2026-44321 · CVSS 7.5
free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
View CVE report →
CVE-2026-44322 · CVSS 7.5
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
View CVE report →
CVE-2026-44325 · CVSS 7.5
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
View CVE report →
CVE-2026-44594 · CVSS 7.5
esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files
View CVE report →
CVE-2026-45678 · CVSS 7.5
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
View CVE report →
CVE-2026-45685 · CVSS 7.5
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
View CVE report →
CVE-2026-45741 · CVSS 7.5
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
View CVE report →
CVE-2026-46377 · CVSS 7.5
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
View CVE report →
CVE-2026-46378 · CVSS 7.5
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
View CVE report →
CVE-2026-46680 · CVSS 7.5
containerd user ID handling bypass allows runAsNonRoot evasion
View CVE report →
CVE-2026-47243 · CVSS 7.5
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
View CVE report →
CVE-2026-47726 · CVSS 7.5
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
View CVE report →
CVE-2026-48020 · CVSS 7.5
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
View CVE report →
CVE-2026-48089 · CVSS 7.5
DevGuard has improper authorization on public assets
View CVE report →
CVE-2026-48491 · CVSS 7.5
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
View CVE report →
CVE-2026-50141 · CVSS 7.5
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
View CVE report →
CVE-2026-50151 · CVSS 7.5
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
View CVE report →
CVE-2026-52807 · CVSS 7.5
Gogs has DOM-based XSS via Milestone Name on New Issue Page
View CVE report →
CVE-2026-52844 · CVSS 7.5
Caddy: Windows `file_server` path authorization bypass via encoded backslash
View CVE report →
CVE-2026-53622 · CVSS 7.5
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
View CVE report →
CVE-2026-54090 · CVSS 7.5
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
View CVE report →
CVE-2026-61549 · CVSS 7.5
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
View CVE report →
CVE-2026-6970 · CVSS 7.5
authd: Primary group ID is incorrectly set to value of UID
View CVE report →
CVE-2026-45738 · CVSS 7.3
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
View CVE report →
CVE-2026-49339 · CVSS 7.1
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
View CVE report →
CVE-2026-50163 · CVSS 7.1
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
View CVE report →