Vulnerabilities
Vulnerable Software
Golang:  >> Go  >> 1.24.13  Security Vulnerabilities
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-04-08
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-04-08
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.
CVSS Score
2.5
EPSS Score
0.002
Published
2026-03-06
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
CVSS Score
6.1
EPSS Score
0.003
Published
2026-03-06
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVSS Score
7.5
EPSS Score
0.007
Published
2026-03-06


Contact Us

Shodan ® - All rights reserved