Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Report generated on: September 09, 2026 at 03:20 UTC

All Products Vulnerability Report

Covered Products

Key Findings for This Reporting Period

  • Total Open Vulnerabilities: Across all products, we are currently tracking 187 open vulnerabilities.
  • Progress: Over the last 12 months, we have fixed 18 vulnerabilities, including 0 critical ones.

12-Month Combined Vulnerability Trend

xychart-beta
    title "New vs. Fixed Vulnerabilities (Last 12 Months)"
    x-axis "Month" ["2025-10", "2025-11", "2025-12", "2026-01", "2026-02", "2026-03", "2026-04", "2026-05", "2026-06", "2026-07", "2026-08", "2026-09"]
    y-axis "Count"
    bar "New" [0, 0, 0, 0, 1, 2, 0, 0, 0, 0, 0, 0]
    bar "Fixed" [0, 0, 0, 0, 6, 10, 0, 0, 0, 1, 1, 0]
MonthNewFixedTotal at Month End
2026-0900187
2026-0801187
2026-0701188
2026-0600189
2026-0500189
2026-0400189
2026-03210189
2026-0216197
2026-0100202
2025-1200202
2025-1100202
2025-1000202

Detailed Vulnerability List

Total Open Vulnerabilities: 187

CVE IdentifierSeverityPackage NameDescription
CVE-2026-56854CRITICALgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-39828HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-46595HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-39827MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
CVE-2026-39833MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
CVE-2026-39834MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write
CVE-2026-46598MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
CVE-2026-56855UNKNOWNgolang.org/x/cryptoPreviously, after a channel has been established, a malicious peer cou …
CVE-2026-78662UNKNOWNgolang.org/x/cryptoPreviously, a channel registered in the mux’s chanList is not usable u …
GO-2026-5932UNKNOWNgolang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-46602HIGHgolang.org/x/imageThe TIFF decoder does not set a limit on the size of tiles in tiled im …
CVE-2026-46603HIGHgolang.org/x/imagegolang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation
CVE-2026-33809MEDIUMgolang.org/x/imagegolang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33812MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files
CVE-2026-33813MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing
CVE-2026-42500MEDIUMgolang.org/x/imagegolang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding
CVE-2026-46599MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46601MEDIUMgolang.org/x/imagegolang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
CVE-2026-46604MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-25681HIGHgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136HIGHgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814HIGHgolang.org/x/netnet/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-39821HIGHgolang.org/x/netgolang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHgolang.org/x/netgolang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-25680MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing
CVE-2026-27141MEDIUMgolang.org/x/netgolang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames
CVE-2026-42502MEDIUMgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42506MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56854CRITICALgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-39828HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-46595HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-39827MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
CVE-2026-39833MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
CVE-2026-39834MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write
CVE-2026-46598MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
CVE-2026-56855UNKNOWNgolang.org/x/cryptoPreviously, after a channel has been established, a malicious peer cou …
CVE-2026-78662UNKNOWNgolang.org/x/cryptoPreviously, a channel registered in the mux’s chanList is not usable u …
GO-2026-5932UNKNOWNgolang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-46602HIGHgolang.org/x/imageThe TIFF decoder does not set a limit on the size of tiles in tiled im …
CVE-2026-46603HIGHgolang.org/x/imagegolang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation
CVE-2026-33809MEDIUMgolang.org/x/imagegolang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33812MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files
CVE-2026-33813MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing
CVE-2026-42500MEDIUMgolang.org/x/imagegolang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding
CVE-2026-46599MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46601MEDIUMgolang.org/x/imagegolang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
CVE-2026-46604MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-25681HIGHgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136HIGHgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814HIGHgolang.org/x/netnet/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-39821HIGHgolang.org/x/netgolang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHgolang.org/x/netgolang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-25680MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing
CVE-2026-27141MEDIUMgolang.org/x/netgolang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames
CVE-2026-42502MEDIUMgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42506MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56854CRITICALgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-39828HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-46595HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-39827MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
CVE-2026-39833MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
CVE-2026-39834MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write
CVE-2026-46598MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
CVE-2026-56855UNKNOWNgolang.org/x/cryptoPreviously, after a channel has been established, a malicious peer cou …
CVE-2026-78662UNKNOWNgolang.org/x/cryptoPreviously, a channel registered in the mux’s chanList is not usable u …
GO-2026-5932UNKNOWNgolang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-46602HIGHgolang.org/x/imageThe TIFF decoder does not set a limit on the size of tiles in tiled im …
CVE-2026-46603HIGHgolang.org/x/imagegolang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation
CVE-2026-33809MEDIUMgolang.org/x/imagegolang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33812MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files
CVE-2026-33813MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing
CVE-2026-42500MEDIUMgolang.org/x/imagegolang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding
CVE-2026-46599MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46601MEDIUMgolang.org/x/imagegolang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
CVE-2026-46604MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-25681HIGHgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136HIGHgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814HIGHgolang.org/x/netnet/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-39821HIGHgolang.org/x/netgolang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHgolang.org/x/netgolang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-25680MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing
CVE-2026-27141MEDIUMgolang.org/x/netgolang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames
CVE-2026-42502MEDIUMgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42506MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56854CRITICALgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-39828HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-46595HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-39827MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
CVE-2026-39833MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
CVE-2026-39834MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write
CVE-2026-46598MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
CVE-2026-56855UNKNOWNgolang.org/x/cryptoPreviously, after a channel has been established, a malicious peer cou …
CVE-2026-78662UNKNOWNgolang.org/x/cryptoPreviously, a channel registered in the mux’s chanList is not usable u …
GO-2026-5932UNKNOWNgolang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-46602HIGHgolang.org/x/imageThe TIFF decoder does not set a limit on the size of tiles in tiled im …
CVE-2026-46603HIGHgolang.org/x/imagegolang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation
CVE-2026-33809MEDIUMgolang.org/x/imagegolang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33812MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files
CVE-2026-33813MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing
CVE-2026-42500MEDIUMgolang.org/x/imagegolang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding
CVE-2026-46599MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46601MEDIUMgolang.org/x/imagegolang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
CVE-2026-46604MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-25681HIGHgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136HIGHgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814HIGHgolang.org/x/netnet/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-39821HIGHgolang.org/x/netgolang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHgolang.org/x/netgolang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-25680MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing
CVE-2026-27141MEDIUMgolang.org/x/netgolang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames
CVE-2026-42502MEDIUMgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42506MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56854CRITICALgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVE-2026-39828HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-46595HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46597HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-39827MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
CVE-2026-39833MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
CVE-2026-39834MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write
CVE-2026-46598MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input
CVE-2026-56855UNKNOWNgolang.org/x/cryptoPreviously, after a channel has been established, a malicious peer cou …
CVE-2026-78662UNKNOWNgolang.org/x/cryptoPreviously, a channel registered in the mux’s chanList is not usable u …
GO-2026-5932UNKNOWNgolang.org/x/cryptoThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-46602HIGHgolang.org/x/imageThe TIFF decoder does not set a limit on the size of tiles in tiled im …
CVE-2026-46603HIGHgolang.org/x/imagegolang.org/x/image/vp8l: golang.org/x/image/vp8l: Denial of Service via excessive memory allocation
CVE-2026-33809MEDIUMgolang.org/x/imagegolang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file
CVE-2026-33812MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service due to excessive memory allocation when parsing malicious font files
CVE-2026-33813MEDIUMgolang.org/x/imagegolang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing
CVE-2026-42500MEDIUMgolang.org/x/imagegolang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding
CVE-2026-46599MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46601MEDIUMgolang.org/x/imagegolang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
CVE-2026-46604MEDIUMgolang.org/x/imagegolang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-25681HIGHgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136HIGHgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814HIGHgolang.org/x/netnet/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-39821HIGHgolang.org/x/netgolang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHgolang.org/x/netgolang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-25680MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing
CVE-2026-27141MEDIUMgolang.org/x/netgolang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames
CVE-2026-42502MEDIUMgolang.org/x/netgolang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-42506MEDIUMgolang.org/x/netgolang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing
CVE-2026-39824UNKNOWNgolang.org/x/sysInvoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-56852HIGHgolang.org/x/textgolang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input

Total Fixed Vulnerabilities (Last 12 Months): 18

CVE IdentifierSeverityPackage NameDescription
GHSA-mpwr-8vm7-h73fMEDIUMsoftware.sslmate.com/src/go-pkcs12package pkcs12: Authentication bypass in Decode functions
CVE-2025-47913HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS
CVE-2025-47914MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages
CVE-2025-58181MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication
CVE-2025-47911MEDIUMgolang.org/x/netgolang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html
CVE-2025-58190MEDIUMgolang.org/x/netgolang.org/x/net/html: Infinite parsing loop in golang.org/x/net
CVE-2025-47913HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS
CVE-2025-47914MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages
CVE-2025-58181MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication
CVE-2025-47911MEDIUMgolang.org/x/netgolang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html
CVE-2025-58190MEDIUMgolang.org/x/netgolang.org/x/net/html: Infinite parsing loop in golang.org/x/net
CVE-2023-36308LOWgithub.com/disintegration/imagingdisintegration Imaging 1.6.2 allows attackers to cause a panic (becaus …
CVE-2025-69725MEDIUMgithub.com/go-chi/chi/v5go-chi/chi: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites
CVE-2025-47913HIGHgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS
CVE-2025-47914MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages
CVE-2025-58181MEDIUMgolang.org/x/cryptogolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication
CVE-2025-47911MEDIUMgolang.org/x/netgolang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html
CVE-2025-58190MEDIUMgolang.org/x/netgolang.org/x/net/html: Infinite parsing loop in golang.org/x/net