LIVE · cybersecurity feed
Live wire
vendor

Golang

14 CVEs published in the last four months. Exploited flaws first.

Critical8
High6
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-4659510criticalcryptoPreviously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type 107d ago
CVE-2026-398219.6criticalnetThe ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label.106d ago
CVE-2026-398339.1criticalcryptoThe in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but nev107d ago
CVE-2026-398319.1criticalcryptoThe Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.co107d ago
CVE-2026-398329.1criticalcryptoWhen adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not se107d ago
CVE-2026-398309.1criticalcryptoA malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the conn107d ago
CVE-2026-398349.1criticalcryptoWhen writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal pa107d ago
CVE-2026-425089.1criticalcryptoPreviously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation.107d ago
CVE-2026-398227.8highgoOn Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when th59d ago
CVE-2026-786627.5highcryptoPreviously, a channel registered in the mux's chanList is not usable until it is established.3d ago
CVE-2026-398297.5highcryptoThe RSA and DSA public key parsers did not enforce size limits on key parameters.107d ago
CVE-2026-466047.5hightiffThe TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.71d ago
CVE-2026-568557.5highcryptoPreviously, after a channel has been established, a malicious peer could send crafted messages that would deadlock3d ago
CVE-2026-465977.5highcryptoAn incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-107d ago

Filter the full tracker by Golang