Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Go standard library — Vulnerabilities & Security Advisories 120

Browse all 120 CVE security advisories affecting Go standard library. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Go standard library provides essential built-in packages for networking, cryptography, and system interaction, serving as the foundational runtime for millions of applications. Despite its robust design, it has recorded approximately 100 Common Vulnerabilities and Exposures (CVEs), primarily stemming from logic errors in parsing or concurrency handling rather than complex exploitation chains. Historically, common vulnerability classes include denial-of-service conditions via malformed input, race conditions in concurrent data structures, and occasional remote code execution flaws within specific subsystems like HTTP servers or crypto implementations. Notable incidents often involve improper validation leading to memory corruption or information disclosure. While the library is generally secure, its widespread adoption means even minor flaws can impact a vast ecosystem. Developers must remain vigilant about patching updates, as the standard library’s central role amplifies the risk of any discovered defect affecting dependent software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-56860 Avoid quadratic complexity in resolvePath in net/url — net/url - - 2026-08-13
CVE-2026-33818 Enforce maximum recursion depth in encoding/asn1 — encoding/asn1 - - 2026-08-13
CVE-2026-56853 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http — net/http - - 2026-08-13
CVE-2026-56858 Fix Javascript regexp context tracking in html/template — html/template - - 2026-08-13
CVE-2026-56859 Add recursion depth guard during decode in encoding/xml — encoding/xml - - 2026-08-13
CVE-2026-56862 Limit handshake messages we are willing to accept post-handshake in crypto/tls — crypto/tls - - 2026-08-13
CVE-2026-46600 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage — net - - 2026-07-21
CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls — crypto/tls - - 2026-07-08
CVE-2026-39822 Root escape via symlink plus trailing slash in os — os - - 2026-07-08
CVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509 — crypto/x509 - - 2026-06-02
CVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textproto — net/textproto - - 2026-06-02
CVE-2026-42504 Quadratic complexity in WordDecoder.DecodeHeader in mime — mime - - 2026-06-02
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna — net/http - - 2026-05-22
CVE-2026-39820 Quadratic string concatentation in consumeComment in net/mail — net/mail 7.5AI High AI 2026-05-07
CVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/template — html/template 6.1AI Medium AI 2026-05-07
CVE-2026-33811 Crash when handling long CNAME response in net — net 7.5AI High AI 2026-05-07
CVE-2026-39826 Escaper bypass leads to XSS in html/template — html/template 5.0AI Medium AI 2026-05-07
CVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mail — net/mail 7.5AI High AI 2026-05-07
CVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil — net/http/httputil 5.3AI Medium AI 2026-05-07
CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net — net 7.5AI High AI 2026-05-07
CVE-2026-32280 Unexpected work during chain building in crypto/x509 — crypto/x509 7.5AI High AI 2026-04-08
CVE-2026-32281 Inefficient policy validation in crypto/x509 — crypto/x509 7.5AI High AI 2026-04-08
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls — crypto/tls 7.5AI High AI 2026-04-08
CVE-2026-32288 Unbounded allocation for old GNU sparse in archive/tar — archive/tar 6.2AI Medium AI 2026-04-08
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 — crypto/x509 6.5AI Medium AI 2026-04-08
CVE-2026-32289 JsBraceDepth Context Tracking Bugs (XSS) in html/template — html/template 6.1AI Medium AI 2026-04-08
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix — internal/syscall/unix 7.7AI High AI 2026-04-08
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template — html/template 6.1 - 2026-03-06
CVE-2026-27138 Panic in name constraint checking for malformed certificates in crypto/x509 — crypto/x509 7.5 - 2026-03-06
CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url — net/url 5.3 - 2026-03-06

This page lists every published CVE security advisory associated with Go standard library. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.