Search CVE reports


Toggle filters

1 – 10 of 26 results


CVE-2025-4674

Medium priority
Needs evaluation

[Unknown description]

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Needs evaluation Needs evaluation Needs evaluation
golang-1.23 Needs evaluation Needs evaluation
golang-1.24 Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-4673

Medium priority

Some fixes available 3 of 32

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Fixed Fixed Needs evaluation
golang-1.23 Needs evaluation Needs evaluation
golang-1.24 Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-22874

Medium priority
Needs evaluation

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Not affected Not affected Needs evaluation
golang-1.23 Needs evaluation Needs evaluation
golang-1.24 Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-22870

Medium priority

Some fixes available 3 of 32

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to ”*.example.com”, a request to ”[::1%25.example.com]:80` will...

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Fixed Fixed Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-22866

Medium priority

Some fixes available 3 of 32

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do...

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Fixed Fixed Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-22865

Medium priority
Needs evaluation

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Not affected Not affected Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show all 15 packages Show less packages

CVE-2025-0913

Medium priority
Needs evaluation

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when...

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Ignored
golang-1.9 Not in release Not in release Ignored
golang-1.10 Not in release Not in release Ignored
golang-1.13 Not in release Ignored Ignored Ignored
golang-1.14 Not in release Not in release Ignored
golang-1.16 Not in release Not in release Ignored Ignored
golang-1.17 Not in release Ignored
golang-1.18 Not in release Ignored Needs evaluation Ignored
golang-1.20 Not in release Ignored Needs evaluation
golang-1.21 Ignored Ignored Needs evaluation
golang-1.22 Ignored Ignored Needs evaluation
golang-1.23 Ignored Ignored
golang-1.24 Not in release Not in release
Show all 15 packages Show less packages

CVE-2024-45341

Medium priority

Some fixes available 3 of 47

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only...

18 affected packages

snapd, golang, golang-1.6, golang-1.8, golang-1.9...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Fixed Fixed Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not affected Needs evaluation
Show all 18 packages Show less packages

CVE-2024-45340

Medium priority
Needs evaluation

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected...

15 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation Needs evaluation
golang-1.21 Needs evaluation Needs evaluation Needs evaluation
golang-1.22 Not affected Not affected Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show all 15 packages Show less packages

CVE-2024-45336

Medium priority

Some fixes available 3 of 31

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event...

16 affected packages

golang-1.22, golang-1.23, golang, golang-1.6, golang-1.8...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-1.22 Fixed Fixed Needs evaluation
golang-1.23 Needs evaluation Needs evaluation Not in release
golang Not in release Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation Not in release
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release Not in release
golang-1.18 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.19 Not in release Not in release Not in release Not in release
golang-1.20 Not in release Needs evaluation Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
Show all 16 packages Show less packages