Search CVE reports


Toggle filters

1 – 10 of 54 results


CVE-2025-0913

Medium priority
Ignored

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when...

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.10 Not in release Not in release Ignored
golang-1.13 Not in release Ignored Ignored Ignored
golang-1.14 Not in release Not in release Ignored
golang-1.16 Not in release Not in release Ignored Ignored
golang-1.17 Not in release Ignored
golang-1.18 Not in release Ignored Ignored
golang-1.20 Not in release Ignored
golang-1.21 Ignored Ignored
golang-1.22 Ignored Ignored
golang-1.23 Ignored Ignored
golang-1.24 Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Ignored
golang-1.9 Not in release Not in release Ignored
Show all 15 packages Show less packages

CVE-2025-4673

Medium priority

Some fixes available 3 of 28

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.10 Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation
golang-1.18 Not in release Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation
golang-1.21 Needs evaluation Needs evaluation
golang-1.22 Fixed Fixed
golang-1.23 Needs evaluation Needs evaluation
golang-1.24 Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2025-22874

Medium priority
Needs evaluation

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release
golang-1.10 Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation
golang-1.18 Not in release Needs evaluation Needs evaluation
golang-1.20 Not in release Needs evaluation
golang-1.21 Needs evaluation Needs evaluation
golang-1.22 Not affected Not affected
golang-1.23 Needs evaluation Needs evaluation
golang-1.24 Not in release Not in release
golang-1.6 Not in release Not in release
golang-1.8 Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2025-22870

Medium priority

Some fixes available 3 of 28

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to ”*.example.com”, a request to ”[::1%25.example.com]:80` will...

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Fixed Fixed Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2025-22866

Medium priority

Some fixes available 3 of 28

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do...

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Fixed Fixed Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2024-45341

Medium priority

Some fixes available 3 of 43

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only...

18 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Fixed Fixed Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not affected Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 18 packages Show less packages

CVE-2024-45336

Medium priority

Some fixes available 3 of 27

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event...

16 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation Not in release
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.19 Not in release Not in release Not in release Not in release
golang-1.20 Not in release Needs evaluation Not in release Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release Not in release
golang-1.22 Fixed Fixed Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 16 packages Show less packages

CVE-2025-22865

Medium priority
Needs evaluation

Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is well formed.

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Not affected Not affected Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2024-45340

Medium priority
Needs evaluation

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected...

15 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Needs evaluation Not in release
golang-1.18 Not in release Needs evaluation Not in release Needs evaluation
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Not affected Not affected Not in release
golang-1.23 Needs evaluation Needs evaluation Not in release
golang-1.24 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 15 packages Show less packages

CVE-2024-34158

Medium priority

Some fixes available 8 of 24

Calling Parse on a ”// +build” build tag line with deeply nested expressions can cause a panic due to stack exhaustion.

14 affected packages

golang, golang-1.10, golang-1.13, golang-1.14, golang-1.16...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Needs evaluation
golang-1.16 Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Fixed Not in release
golang-1.18 Not in release Fixed Fixed Fixed
golang-1.19 Not in release Not in release Not in release
golang-1.20 Not in release Needs evaluation Not in release
golang-1.21 Needs evaluation Needs evaluation Not in release
golang-1.22 Fixed Fixed Fixed
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Needs evaluation
Show all 14 packages Show less packages