Search CVE reports


Toggle filters

1 – 10 of 1518 results


CVE-2026-34986

Medium priority
Needs evaluation

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to...

3 affected packages

golang-github-go-jose-go-jose, golang-github-go-jose-go-jose.v3, golang-gopkg-square-go-jose.v2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-jose-go-jose Needs evaluation Not in release
golang-github-go-jose-go-jose.v3 Not in release Not in release
golang-gopkg-square-go-jose.v2 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33817

Medium priority
Needs evaluation

Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt

2 affected packages

golang-github-boltdb-bolt, golang-github-coreos-bbolt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-boltdb-bolt Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-github-coreos-bbolt Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-13929

Medium priority
Ignored

(GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-34165

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-33762

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-2370

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-32287

Medium priority
Needs evaluation

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

1 affected package

golang-github-antchfx-xpath

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xpath Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-32286

Medium priority
Needs evaluation

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

1 affected package

golang-github-jackc-pgproto3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-jackc-pgproto3 Needs evaluation Not in release
Show less packages

CVE-2026-32285

Medium priority
Needs evaluation

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

1 affected package

golang-github-buger-jsonparser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-buger-jsonparser Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-13436

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages