Overview
- Go standard library
- net/mail
- net/mail
29 Oct 2025
Published
09 Dec 2025
Updated
CVSS
Pending
EPSS
0.65%
KEV
Description
The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- FasterXML
- jackson-databind
23 Jun 2026
Published
24 Jun 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
1.00%
KEV
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go toolchain
- cmd/cgo
- cmd/cgo
05 Feb 2026
Published
10 Sep 2026
Updated
CVSS
Pending
EPSS
0.49%
KEV
Description
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- os
- os
08 Jul 2026
Published
08 Jul 2026
Updated
CVSS
Pending
EPSS
0.23%
KEV
Description
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- html/template
- html/template
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.33%
KEV
Description
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- net/mail
- net/mail
07 May 2026
Published
18 Sep 2026
Updated
CVSS
Pending
EPSS
0.87%
KEV
Description
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Apache Software Foundation
- Apache Log4j Core
- org.apache.logging.log4j:log4j-core
10 Apr 2026
Published
10 Apr 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
1.19%
KEV
Description
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters.
The impact depends on the StAX implementation in use:
* JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.
* Alternative StAX implementations (e.g., Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.
Users are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- internal/syscall/unix
- internal/syscall/unix
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.29%
KEV
Description
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go standard library
- crypto/x509
- crypto/x509
29 Oct 2025
Published
20 Nov 2025
Updated
CVSS
Pending
EPSS
0.41%
KEV
Description
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- Go toolchain
- cmd/compile
- cmd/compile
08 Apr 2026
Published
13 Apr 2026
Updated
CVSS
Pending
EPSS
0.18%
KEV
Description
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.
Statistics
- 1 Post
Last activity: 2 hours ago