Information on source package golang-1.19

Available versions

ReleaseVersion
bookworm1.19.8-2
sid1.19.8-2

Open issues

BugbookwormsidDescription
CVE-2023-29400vulnerablevulnerableTemplates containing actions in unquoted HTML attributes (e.g. "attr={ ...
CVE-2023-24540vulnerablevulnerableNot all valid JavaScript whitespace characters are considered to be wh ...
CVE-2023-24539vulnerablevulnerableAngle brackets (<>) are not considered dangerous characters when inser ...

Resolved issues

BugDescription
CVE-2023-24538Templates do not properly consider backticks (`) as Javascript string ...
CVE-2023-24537Calling any of the Parse functions on Go source code which contains // ...
CVE-2023-24536Multipart form parsing can consume large amounts of CPU and memory whe ...
CVE-2023-24534HTTP and MIME header parsing can allocate large amounts of memory, eve ...
CVE-2023-24532The ScalarMult and ScalarBaseMult methods of the P256 Curve may return ...
CVE-2022-41725A denial of service is possible from excessive resource consumption in ...
CVE-2022-41724Large handshake records may cause panics in crypto/tls. Both clients a ...
CVE-2022-41723A maliciously crafted HTTP/2 stream could cause excessive CPU consumpt ...
CVE-2022-41722A path traversal vulnerability exists in filepath.Clean on Windows. On ...
CVE-2022-41720On Windows, restricted files can be accessed via os.DirFS and http.Dir ...
CVE-2022-41717An attacker can cause excessive memory growth in a Go server accepting ...
CVE-2022-41716Due to unsanitized NUL values, attackers may be able to maliciously se ...
CVE-2022-41715Programs which compile regular expressions from untrusted sources may ...
CVE-2022-32190JoinPath and URL.JoinPath do not remove ../ path elements appended to ...
CVE-2022-32189A too-short encoded message can cause a panic in Float.GobDecode and R ...
CVE-2022-32148Improper exposure of client IP addresses in net/http before Go 1.17.12 ...
CVE-2022-30635Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.1 ...
CVE-2022-30633Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 ...
CVE-2022-30632Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and ...
CVE-2022-30631Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17. ...
CVE-2022-30630Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18. ...
CVE-2022-27664In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ...
CVE-2022-2880Requests forwarded by ReverseProxy include the raw query parameters fr ...
CVE-2022-2879Reader.Read does not set a limit on the maximum size of file headers. ...
CVE-2022-1962Uncontrolled recursion in the Parse functions in go/parser before Go 1 ...
CVE-2022-1705Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 cli ...

Search for package or bug name: Reporting problems