Known Vulnerabilities for products from Golang
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Golang".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-79658 json | Not Provided | 2026-08-25 | 2026-08-29 | |
| CVE-2026-78662 json | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood... | Not Provided | 2026-09-02 | 2026-09-04 |
| CVE-2026-64679 json | Not Provided | 2026-08-21 | 2026-08-25 | |
| CVE-2026-56855 json | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire... | Not Provided | 2026-09-02 | 2026-09-04 |
| CVE-2026-52814 json | Not Provided | 2026-06-24 | 2026-06-25 | |
| CVE-2026-50138 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-49329 json | Not Provided | 2026-09-01 | 2026-09-01 | |
| CVE-2026-48154 json | Not Provided | 2026-08-04 | 2026-08-05 | |
| CVE-2026-46604 json | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. | Not Provided | 2026-06-26 | 2026-07-01 |
| CVE-2026-46603 json | Not Provided | 2026-08-14 | 2026-08-14 | |
| CVE-2026-46598 json | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used. | Not Provided | 2026-05-22 | 2026-07-23 |
| CVE-2026-46597 json | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inp... | Not Provided | 2026-05-22 | 2026-07-23 |
| CVE-2026-46595 json | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback... | Not Provided | 2026-05-22 | 2026-09-11 |
| CVE-2026-45135 json | Not Provided | 2026-06-23 | 2026-06-23 | |
| CVE-2026-42508 json | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key... | Not Provided | 2026-05-22 | 2026-09-11 |
| CVE-2026-42506 json | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to ex... | Not Provided | 2026-05-22 | 2026-07-23 |
| CVE-2026-42505 json | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-... | Not Provided | 2026-07-08 | 2026-07-13 |
| CVE-2026-42502 json | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to ex... | Not Provided | 2026-05-22 | 2026-07-23 |
| CVE-2026-42501 json | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database va... | Not Provided | 2026-05-07 | 2026-05-13 |
| CVE-2026-42499 json | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | Not Provided | 2026-05-07 | 2026-09-11 |
Known software with vulnerabilities from Golang
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Golang | Crypto | - |
| Application | Golang | Go | 0.0.0-20201203163018-be400aefbc4c |
| Application | Golang | Net | 2018-07-02 |
| Application | Golang | Package Ssh | 0.0.0-20200220183623-bac4c82f6975 |
| Application | Golang | Protobuf | 0.1 |
| Application | Golang | Text | 0.1.0 |