Information on source package golang-1.24

Available versions

ReleaseVersion
trixie1.24.4-1
forky1.24.9-1
sid1.24.9-1

Open issues

BugtrixieforkysidDescription
CVE-2025-61729vulnerablevulnerablevulnerableWithin HostnameError.Error(), when constructing an error string, there ...
CVE-2025-61727vulnerablevulnerablevulnerableAn excluded subdomain constraint in a certificate chain does not restr ...
CVE-2025-61725vulnerable (no DSA)fixedfixedThe ParseAddress function constructs domain-literal address components ...
CVE-2025-61724vulnerable (no DSA)fixedfixedThe Reader.ReadResponse function constructs a response string through ...
CVE-2025-61723vulnerable (no DSA)fixedfixedThe processing time for parsing some invalid inputs scales non-linearl ...
CVE-2025-58189vulnerable (no DSA)fixedfixedWhen Conn.Handshake fails during ALPN negotiation the error contains a ...
CVE-2025-58188vulnerable (no DSA)fixedfixedValidating certificate chains which contain DSA public keys can cause ...
CVE-2025-58187vulnerable (no DSA)fixedfixedDue to the design of the name constraint checking algorithm, the proce ...
CVE-2025-58186vulnerable (no DSA)fixedfixedDespite HTTP headers having a default limit of 1MB, the number of cook ...
CVE-2025-58185vulnerable (no DSA)fixedfixedParsing a maliciously crafted DER payload could allocate large amounts ...
CVE-2025-58183vulnerable (no DSA)fixedfixedtar.Reader does not set a maximum size on the number of sparse region ...
CVE-2025-47912vulnerable (no DSA)fixedfixedThe Parse function permits values other than IPv6 addresses to be incl ...
CVE-2025-47907vulnerable (no DSA)fixedfixedCancelling a query (e.g. by cancelling the context passed to one of th ...
CVE-2025-47906vulnerable (no DSA)fixedfixedIf the PATH environment variable contains paths which are executables ...
CVE-2025-4674vulnerable (no DSA)fixedfixedThe go command may execute unexpected commands when operating in untru ...
CVE-2024-8244vulnerable (no DSA)vulnerablevulnerableThe filepath.Walk and filepath.WalkDir functions are documented as not ...

Resolved issues

BugDescription
CVE-2025-47910When using http.CrossOriginProtection, the AddInsecureBypassPattern me ...
CVE-2025-22874Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsag ...
CVE-2025-22873
CVE-2025-22871The net/http package improperly accepts a bare LF as a line terminator ...
CVE-2025-22870Matching of hosts against proxy patterns can improperly treat an IPv6 ...
CVE-2025-22867On Darwin, building a Go module which contains CGO can trigger arbitra ...
CVE-2025-22866Due to the usage of a variable time instruction in the assembly implem ...
CVE-2025-22865Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT ...
CVE-2025-4673Proxy-Authorization and Proxy-Authenticate headers persisted on cross- ...
CVE-2025-0913os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and ...
CVE-2024-45341A certificate with a URI which has a IPv6 address with a zone ID may i ...
CVE-2024-45340Credentials provided via the new GOAUTH feature were not being properl ...
CVE-2024-45336The HTTP client drops sensitive headers after following a cross-domain ...

Search for package or bug name: Reporting problems