Information on source package golang-1.25

Available versions

ReleaseVersion
forky1.25.12-1
sid1.25.12-1

Resolved issues

BugDescription
CVE-2026-42507When returning errors, functions in the net/textproto package would in ...
CVE-2026-42505Handshakes which used Encrypted Client Hello could be de-anonymized by ...
CVE-2026-42504Decoding a maliciously-crafted MIME header containing many invalid enc ...
CVE-2026-42501A malicious module proxy can exploit a flaw in the go command's valida ...
CVE-2026-42499Pathological inputs could cause DoS through consumePhrase when parsing ...
CVE-2026-39836The Dial and LookupPort functions panic on Windows when provided with ...
CVE-2026-39826If a trusted template author were to write a <script> tag containing a ...
CVE-2026-39825ReverseProxy can forward queries containing parameters not visible to ...
CVE-2026-39823CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
CVE-2026-39822On Unix systems, opening a file in an os.Root improperly follows symli ...
CVE-2026-39820Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
CVE-2026-39819The "go bug" command writes to two files with predictable names in the ...
CVE-2026-39817The "go tool pack" subcommand (usually used only by the compiler as an ...
CVE-2026-33811When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...
CVE-2026-33810When verifying a certificate chain containing excluded DNS constraints ...
CVE-2026-32289Context was not properly tracked across template branches for JS templ ...
CVE-2026-32288tar.Reader can allocate an unbounded amount of memory when reading a m ...
CVE-2026-32283If one side of the TLS connection sends multiple key update messages p ...
CVE-2026-32282On Linux, if the target of Root.Chmod is replaced with a symlink while ...
CVE-2026-32281Validating certificate chains which use policies is unexpectedly ineff ...
CVE-2026-32280During chain building, the amount of work that is done is not correctl ...
CVE-2026-27145(*x509.Certificate).VerifyHostname previously called matchHostnames in ...
CVE-2026-27144The compiler is meant to unwrap pointers which are the operands of a m ...
CVE-2026-27143Arithmetic over induction variables in loops were not correctly checke ...
CVE-2026-27142Actions which insert URLs into the content attribute of HTML meta tags ...
CVE-2026-27140SWIG file names containing 'cgo' and well-crafted payloads could lead ...
CVE-2026-27139On Unix platforms, when listing the contents of a directory using File ...
CVE-2026-27138Certificate verification can panic when a certificate in the chain has ...
CVE-2026-27137When verifying a certificate chain which contains a certificate contai ...
CVE-2026-25679url.Parse insufficiently validated the host/authority component and ac ...
CVE-2025-68121During session resumption in crypto/tls, if the underlying Config has ...
CVE-2025-68119Downloading and building modules with malicious version strings can ca ...
CVE-2025-61732A discrepancy between how Go and C/C++ comments were parsed allowed fo ...
CVE-2025-61731Building a malicious file with cmd/go can cause can cause a write to a ...
CVE-2025-61730During the TLS 1.3 handshake if multiple messages are sent in records ...
CVE-2025-61729Within HostnameError.Error(), when constructing an error string, there ...
CVE-2025-61728archive/zip uses a super-linear file name indexing algorithm that is i ...
CVE-2025-61727An excluded subdomain constraint in a certificate chain does not restr ...
CVE-2025-61726The net/url package does not set a limit on the number of query parame ...
CVE-2025-61725The ParseAddress function constructs domain-literal address components ...
CVE-2025-61724The Reader.ReadResponse function constructs a response string through ...
CVE-2025-61723The processing time for parsing some invalid inputs scales non-linearl ...
CVE-2025-58189When Conn.Handshake fails during ALPN negotiation the error contains a ...
CVE-2025-58188Validating certificate chains which contain DSA public keys can cause ...
CVE-2025-58187Due to the design of the name constraint checking algorithm, the proce ...
CVE-2025-58186Despite HTTP headers having a default limit of 1MB, the number of cook ...
CVE-2025-58185Parsing a maliciously crafted DER payload could allocate large amounts ...
CVE-2025-58183tar.Reader does not set a maximum size on the number of sparse region ...
CVE-2025-47912The Parse function permits values other than IPv6 addresses to be incl ...
CVE-2025-47910When using http.CrossOriginProtection, the AddInsecureBypassPattern me ...

Search for package or bug name: Reporting problems