Overview
- FasterXML
- jackson-core
25 Jun 2025
Published
25 Jun 2025
Updated
CVSS v4.0
HIGH (8.7)
EPSS
0.77%
KEV
Description
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- encoding/pem
- encoding/pem
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.66%
KEV
Description
The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- html/template
- html/template
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.39%
KEV
Description
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- archive/tar
- archive/tar
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.18%
KEV
Description
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net/http/httputil
- net/http/httputil
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.41%
KEV
Description
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&a2=x&...&a10000=x&hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- golang.org/x/net
- golang.org/x/net/http2
- golang.org/x/net/http2
07 May 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.78%
KEV
Description
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net
- net
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.62%
KEV
Description
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net/http
- net/http
29 Oct 2025
Published
04 Nov 2025
Updated
CVSS
Pending
EPSS
0.56%
KEV
Description
Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go toolchain
- cmd/compile
- cmd/compile
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.66%
KEV
Description
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Go standard library
- net/mail
- net/mail
07 May 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.80%
KEV
Description
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Statistics
- 1 Post
Last activity: 3 hours ago