Known Vulnerabilities for Go-slug by HashiCorp
Listed below are 2 of the newest known vulnerabilities associated with "Go-slug" by "HashiCorp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86434 json | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNor... | Not Provided | 2026-09-07 | 2026-09-07 |
| CVE-2026-86085 json | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/r... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-82396 json | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-77116 json | Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in us... | Not Provided | 2026-08-23 | 2026-08-23 |
| CVE-2026-75908 json | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This i... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-73331 json | CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creatio... | Not Provided | 2026-08-12 | 2026-08-14 |
| CVE-2026-73159 json | Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-htm... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72720 json | Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has ... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71285 json | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-08-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hashicorp | Go-slug | 0.5.0 | |||
| Application | Hashicorp | Go-slug | 0.4.3 | |||
| Application | Hashicorp | Go-slug | 0.4.2 | |||
| Application | Hashicorp | Go-slug | 0.4.1 | |||
| Application | Hashicorp | Go-slug | 0.4.0 | |||
| Application | Hashicorp | Go-slug | 0.3.1 | |||
| Application | Hashicorp | Go-slug | 0.3.0 | |||
| Application | Hashicorp | Go-slug | 0.2.0 | |||
| Application | Hashicorp | Go-slug | 0.1.0 |