Information on source package golang-1.24

Available versions

ReleaseVersion
trixie1.24.4-1
forky1.24.9-1
sid1.24.9-1

Open issues

BugtrixieforkysidDescription
CVE-2025-61725vulnerable (no DSA)fixedfixednet/mail: excessive CPU consumption in ParseAddress
CVE-2025-61724vulnerable (no DSA)fixedfixednet/textproto: excessive CPU consumption in Reader.ReadResponse
CVE-2025-61723vulnerable (no DSA)fixedfixedencoding/pem: quadratic complexity when parsing some invalid inputs
CVE-2025-58189vulnerable (no DSA)fixedfixedcrypto/tls: ALPN negotiation errors can contain arbitrary text
CVE-2025-58188vulnerable (no DSA)fixedfixedcrypto/x509: panic when validating certificates with DSA public keys
CVE-2025-58187vulnerable (no DSA)fixedfixedcrypto/x509: quadratic complexity when checking name constraints
CVE-2025-58186vulnerable (no DSA)fixedfixednet/http: lack of limit when parsing cookies can cause memory exhaustion
CVE-2025-58185vulnerable (no DSA)fixedfixedencoding/asn1: pre-allocating memory when parsing DER payload can cause memory exhaustion
CVE-2025-58183vulnerable (no DSA)fixedfixedarchive/tar: unbounded allocation when parsing GNU sparse map
CVE-2025-47912vulnerable (no DSA)fixedfixednet/url: insufficient validation of bracketed IPv6 hostnames
CVE-2025-47907vulnerable (no DSA)fixedfixedCancelling a query (e.g. by cancelling the context passed to one of th ...
CVE-2025-47906vulnerable (no DSA)fixedfixedIf the PATH environment variable contains paths which are executables ...
CVE-2025-4674vulnerable (no DSA)fixedfixedThe go command may execute unexpected commands when operating in untru ...
CVE-2024-8244vulnerable (no DSA)vulnerablevulnerableThe filepath.Walk and filepath.WalkDir functions are documented as not ...

Resolved issues

BugDescription
CVE-2025-47910When using http.CrossOriginProtection, the AddInsecureBypassPattern me ...
CVE-2025-22874Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsag ...
CVE-2025-22873
CVE-2025-22871The net/http package improperly accepts a bare LF as a line terminator ...
CVE-2025-22870Matching of hosts against proxy patterns can improperly treat an IPv6 ...
CVE-2025-22867On Darwin, building a Go module which contains CGO can trigger arbitra ...
CVE-2025-22866Due to the usage of a variable time instruction in the assembly implem ...
CVE-2025-22865Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT ...
CVE-2025-4673Proxy-Authorization and Proxy-Authenticate headers persisted on cross- ...
CVE-2025-0913os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and ...
CVE-2024-45341A certificate with a URI which has a IPv6 address with a zone ID may i ...
CVE-2024-45340Credentials provided via the new GOAUTH feature were not being properl ...
CVE-2024-45336The HTTP client drops sensitive headers after following a cross-domain ...

Search for package or bug name: Reporting problems