go-standard-library
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting go-standard-library.
- CVE-2026-56862Limit handshake messages we are willing to accept post-handshake in crypto/tls7.5
- CVE-2026-56858Fix Javascript regexp context tracking in html/template6.1
- CVE-2026-56853Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http7.5
- CVE-2026-56860Avoid quadratic complexity in resolvePath in net/url5.9
- CVE-2026-56859Add recursion depth guard during decode in encoding/xml7.5
- CVE-2026-33818Enforce maximum recursion depth in encoding/asn17.5
- CVE-2026-46600Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage7.5
- CVE-2026-42505Invoking Encrypted Client Hello privacy leak in crypto/tls5.3
- CVE-2026-39822Root escape via symlink plus trailing slash in os7.8
- CVE-2026-42507Arbitrary inputs are included in errors without any escaping in net/textproto5.3
- CVE-2026-42504Quadratic complexity in WordDecoder.DecodeHeader in mime7.5
- CVE-2026-27145Inefficient candidate hostname parsing in crypto/x5096.5
- CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna9.6
- CVE-2026-39820Quadratic string concatentation in consumeComment in net/mail7.5
- CVE-2026-39826Escaper bypass leads to XSS in html/template6.1