Report generated on: February 07, 2026 at 03:20 UTC
- Total Open Vulnerabilities: Across all products, we are currently tracking 12 open vulnerabilities.
- Progress: Over the last 12 months, we have fixed 10 vulnerabilities, including 0 critical ones.
xychart-beta
title "New vs. Fixed Vulnerabilities (Last 12 Months)"
x-axis "Month" ["2025-03", "2025-04", "2025-05", "2025-06", "2025-07", "2025-08", "2025-09", "2025-10", "2025-11", "2025-12", "2026-01", "2026-02"]
y-axis "Count"
bar "New" [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
bar "Fixed" [0, 0, 0, 0, 0, 3, 7, 0, 0, 0, 0, 0]
| Month | New | Fixed | Total at Month End |
| 2026-02 | 0 | 0 | 12 |
| 2026-01 | 0 | 0 | 12 |
| 2025-12 | 0 | 0 | 12 |
| 2025-11 | 0 | 0 | 12 |
| 2025-10 | 0 | 0 | 12 |
| 2025-09 | 0 | 7 | 12 |
| 2025-08 | 0 | 3 | 19 |
| 2025-07 | 0 | 0 | 22 |
| 2025-06 | 0 | 0 | 22 |
| 2025-05 | 0 | 0 | 22 |
| 2025-04 | 0 | 0 | 22 |
| 2025-03 | 0 | 0 | 22 |
| CVE Identifier | Severity | Package Name | Description |
| CVE-2025-47914 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages |
| CVE-2025-58181 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication |
| CVE-2023-36308 | LOW | github.com/disintegration/imaging | disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ... |
| CVE-2025-47914 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages |
| CVE-2025-58181 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication |
| CVE-2023-36308 | LOW | github.com/disintegration/imaging | disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ... |
| CVE-2025-47914 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages |
| CVE-2025-58181 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication |
| CVE-2025-47914 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages |
| CVE-2025-58181 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication |
| CVE-2025-47914 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages |
| CVE-2025-58181 | MEDIUM | golang.org/x/crypto | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication |
| CVE Identifier | Severity | Package Name | Description |
| CVE-2025-22869 | HIGH | golang.org/x/crypto | golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh |
| CVE-2025-22870 | MEDIUM | golang.org/x/net | golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net |
| CVE-2025-22872 | MEDIUM | golang.org/x/net | golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net |
| CVE-2025-22869 | HIGH | golang.org/x/crypto | golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh |
| CVE-2025-22870 | MEDIUM | golang.org/x/net | golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net |
| CVE-2025-22872 | MEDIUM | golang.org/x/net | golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net |
| CVE-2025-22869 | HIGH | golang.org/x/crypto | golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh |
| CVE-2025-22870 | MEDIUM | golang.org/x/net | golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net |
| CVE-2025-22872 | MEDIUM | golang.org/x/net | golang.org/x/net/html: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net |
| GHSA-vrw8-fxc6-2r93 | MEDIUM | github.com/go-chi/chi/v5 | chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes |