<?xml version="1.0" encoding="utf-8"?>
            <?xml-stylesheet type="text/xsl" href="/preview.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
<atom:link href="https://stephenslab.top/feed/0d9cc5d3-20c2-4021-bda4-45769f953be5.xml" rel="self" type="application/rss+xml" />
    <title>Vulnerability Reports - Go Packages</title>
    <link>https://pkg.go.dev/vuln/list</link>
    <description><![CDATA[Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.]]></description>
    <lastBuildDate>Fri, 15 May 2026 16:11:32 -0400</lastBuildDate>
    <generator>Rss Everything</generator>
    <ttl>360</ttl>



<item>




<guid isPermaLink="false">caf2de3a268947189db19f82d30166af</guid>
<pubDate>Thu, 07 May 2026 17:01:33 -0400</pubDate>
<title>GO-2026-4986
        
        
  
  
    standard library
  

      
      
        
  
  
    
    
      
        
          CVE-2026-39820
        
      
      Affects:
       
          net/mail
        
      
      Published: May 07, 2026
      
      
      
    

    
      Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
    
  

      
    
      
        
          GO-2026-4984
        
        
  
  
    standard library
  

      
      </title>
<link>https://pkg.go.dev/vuln/GO-2026-4986</link>
<description><![CDATA[CVE-2026-33812, golang.org/x/image, Published: Apr 21, 2026</li>
      
      
      
    </ul>

    
      <p>Parsing a malicious font file can cause excessive memory allocation.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4961">GO-2026-4961</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33813
        </li>
      
      <li class="go-textSubtle">Affects:
       
          golang.org/x/image
        
      </li>
      <li class="go-textSubtle">Published: Apr 21, 2026</li>
      
      
      
    </ul>

    
      <p>Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4947">GO-2026-4947</a>
        </h2>
        
  
  
    <span class="go-Chip go-Chip-inverted">standard library</span>
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-32280
        </li>
      
      <li class="go-textSubtle">Affects:
       
          crypto/x509
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4946">GO-2026-4946</a>
        </h2>
        
  
  
    <span class="go-Chip go-Chip-inverted">standard library</span>
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-32281
        </li>
      
      <li class="go-textSubtle">Affects:
       
          crypto/x509
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.

This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4924">GO-2026-4924</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2025-68153, GHSA-245v-p8fj-vwm2
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/juju/juju
        
      </li>
      <li class="go-textSubtle">Published: Apr 06, 2026, Unreviewed, Juju has a resource poisoning vulnerability in github.com/juju/juju.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/juju/juju from v2.9 before v2.9.56, from v3.6 before v3.6.19.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ba57e8916b8731538caf389a38c6943a</guid>
<pubDate>Wed, 08 Apr 2026 12:12:42 -0400</pubDate>
<title>GO-2026-4920</title>
<link>https://pkg.go.dev/vuln/GO-2026-4920</link>
<description><![CDATA[CVE-2026-34940, GHSA-324q-cwx9-7crr, github.com/kubeai-project/kubeai, Published: Apr 06, 2026, Unreviewed, KubeAI: OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model pods in github.com/kubeai-project/kubeai


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">de720fe5838f0a6e7ef154bb45156e29</guid>
<pubDate>Wed, 01 Apr 2026 14:57:20 -0400</pubDate>
<title>GO-2026-4919</title>
<link>https://pkg.go.dev/vuln/GO-2026-4919</link>
<description><![CDATA[CVE-2026-33634, GHSA-69fq-xp46-6x23, github.com/aquasecurity/trivy, Published: Apr 01, 2026</li>
      
      
      
    </ul>

    
      <p>On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4918">GO-2026-4918</a>
        </h2>
        
  
  
    <span class="go-Chip go-Chip-inverted">standard library</span>
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33814
        </li>
      
      <li class="go-textSubtle">Affects:
       
          golang.org/x/net, net/http
        
      </li>
      <li class="go-textSubtle">Published: May 07, 2026</li>
      
      
      
    </ul>

    
      <p>When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4916">GO-2026-4916</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-26233, GHSA-247x-7qw8-fp98
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/mattermost/mattermost-server
        
      </li>
      <li class="go-textSubtle">Published: Apr 02, 2026, Unreviewed, Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/mattermost/mattermost-server from v8.0.0-20260105080200-d27a2195068d before v8.0.0-20260217110922-b7d4a1f1f59b.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a1d8eacca9797b410fe721cc1c40c281</guid>
<pubDate>Thu, 02 Apr 2026 17:10:03 -0400</pubDate>
<title>GO-2026-4915</title>
<link>https://pkg.go.dev/vuln/GO-2026-4915</link>
<description><![CDATA[CVE-2026-34388, GHSA-w254-4hp5-7cvv, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint in github.com/fleetdm/fleet


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">28a31072b9479a8dc9761290a6bc060e</guid>
<pubDate>Thu, 02 Apr 2026 17:09:52 -0400</pubDate>
<title>GO-2026-4914</title>
<link>https://pkg.go.dev/vuln/GO-2026-4914</link>
<description><![CDATA[CVE-2026-34385, GHSA-v895-833r-8c45, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the database in github.com/fleetdm/fleet


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ff0c262396aeb3fc22e838e617bf902a</guid>
<pubDate>Thu, 02 Apr 2026 17:09:47 -0400</pubDate>
<title>GO-2026-4913</title>
<link>https://pkg.go.dev/vuln/GO-2026-4913</link>
<description><![CDATA[CVE-2026-34386, GHSA-9p23-p2m4-2r4m, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global admin in github.com/fleetdm/fleet


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1ab37dbefe61d5a12eb387f3d157fbd4</guid>
<pubDate>Thu, 02 Apr 2026 17:09:43 -0400</pubDate>
<title>GO-2026-4912</title>
<link>https://pkg.go.dev/vuln/GO-2026-4912</link>
<description><![CDATA[CVE-2026-34389, GHSA-4f9r-x588-pp2h, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet's user account creation via invite does not enforce invited email address in github.com/fleetdm/fleet


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1ef40f5977ece8a80b9040beb2e79f8a</guid>
<pubDate>Thu, 02 Apr 2026 17:09:38 -0400</pubDate>
<title>GO-2026-4911</title>
<link>https://pkg.go.dev/vuln/GO-2026-4911</link>
<description><![CDATA[CVE-2026-33990, GHSA-x2f5-332j-9xwq, github.com/docker/model-runner, Published: Apr 02, 2026, Unreviewed, Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF) in github.com/docker/model-runner


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">67a42b8ea5443d05e9efc6704114d9ea</guid>
<pubDate>Tue, 07 Apr 2026 12:25:06 -0400</pubDate>
<title>GO-2026-4910</title>
<link>https://pkg.go.dev/vuln/GO-2026-4910</link>
<description><![CDATA[CVE-2026-34165, GHSA-jhf3-xxhw-2wpp, github.com/go-git/go-git, github.com/go-git/go-git/v4, and 1 more, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Maliciously crafted idx file can cause asymmetric memory consumption in github.com/go-git/go-git</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4909">GO-2026-4909</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33762, GHSA-gm2x-2g9h-ccm8
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/go-git/go-git, github.com/go-git/go-git/v4, and 1 more
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Missing validation decoding Index v4 files leads to panic in github.com/go-git/go-git</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4907">GO-2026-4907</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33027, GHSA-m8p8-53vf-8357
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/0xJacky/Nginx-UI
        
      </li>
      <li class="go-textSubtle">Published: Apr 02, 2026, Unreviewed, Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">435c1db32c8fa085dccf2cd8c4ce2881</guid>
<pubDate>Thu, 02 Apr 2026 17:09:24 -0400</pubDate>
<title>GO-2026-4906</title>
<link>https://pkg.go.dev/vuln/GO-2026-4906</link>
<description><![CDATA[CVE-2026-33028, GHSA-m468-xcm6-fxg4, github.com/0xJacky/Nginx-UI, github.com/uozi-tech/cosy, Published: Apr 02, 2026, Unreviewed, nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">33778b6901e16fc77309a357714888da</guid>
<pubDate>Thu, 02 Apr 2026 17:09:19 -0400</pubDate>
<title>GO-2026-4905</title>
<link>https://pkg.go.dev/vuln/GO-2026-4905</link>
<description><![CDATA[CVE-2026-27018, GHSA-jjwv-57xh-xr6r, github.com/gotenberg/gotenberg/v7, github.com/gotenberg/gotenberg/v8, Published: Apr 02, 2026, Unreviewed, Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3) in github.com/gotenberg/gotenberg


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7eeebb2dae1ae1eefe166ab599bbd72e</guid>
<pubDate>Thu, 02 Apr 2026 17:09:13 -0400</pubDate>
<title>GO-2026-4904</title>
<link>https://pkg.go.dev/vuln/GO-2026-4904</link>
<description><![CDATA[CVE-2026-33032, GHSA-h6c2-x2m2-mwhf, github.com/0xJacky/Nginx-UI, Published: Apr 02, 2026, Unreviewed, nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">9e52d4ae49315cae69dfa662ecb7114d</guid>
<pubDate>Thu, 02 Apr 2026 17:09:08 -0400</pubDate>
<title>GO-2026-4903</title>
<link>https://pkg.go.dev/vuln/GO-2026-4903</link>
<description><![CDATA[CVE-2026-33026, GHSA-fhh2-gg7w-gwpq, github.com/0xJacky/Nginx-UI, Published: Apr 02, 2026, Unreviewed, nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3551ced23cd4eb1b06cd02d9abc23450</guid>
<pubDate>Thu, 02 Apr 2026 17:09:04 -0400</pubDate>
<title>GO-2026-4902</title>
<link>https://pkg.go.dev/vuln/GO-2026-4902</link>
<description><![CDATA[CVE-2026-33029, GHSA-cp8r-8jvw-v3qg, github.com/0xJacky/Nginx-UI, Published: Apr 02, 2026, Unreviewed, nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">4618d58865d80bec5fb605d22c289ac5</guid>
<pubDate>Thu, 02 Apr 2026 17:08:54 -0400</pubDate>
<title>GO-2026-4901</title>
<link>https://pkg.go.dev/vuln/GO-2026-4901</link>
<description><![CDATA[CVE-2026-33030, GHSA-5hf2-vhj6-gj9m, github.com/0xJacky/nginx-ui, Published: Apr 02, 2026, Unreviewed, nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">736c9d9c82c5dc7b686f0f6c9a30e094</guid>
<pubDate>Thu, 02 Apr 2026 17:08:47 -0400</pubDate>
<title>GO-2026-4899</title>
<link>https://pkg.go.dev/vuln/GO-2026-4899</link>
<description><![CDATA[GHSA-c279-989m-238f, github.com/bishopfox/sliver, Published: Apr 02, 2026, Unreviewed, Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted in github.com/bishopfox/sliver


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">30a86692cedc567fdf8873a19115beba</guid>
<pubDate>Thu, 02 Apr 2026 17:08:46 -0400</pubDate>
<title>GO-2026-4897</title>
<link>https://pkg.go.dev/vuln/GO-2026-4897</link>
<description><![CDATA[GHSA-46wh-3698-f2cx, github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more, Published: Apr 02, 2026, Unreviewed, Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186) in github.com/traefik/traefik


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e674eea36101b14dc41f5bd275fa41bc</guid>
<pubDate>Thu, 02 Apr 2026 17:08:34 -0400</pubDate>
<title>GO-2026-4896</title>
<link>https://pkg.go.dev/vuln/GO-2026-4896</link>
<description><![CDATA[CVE-2026-34204, GHSA-3rh2-v3gr-35p9, github.com/minio/minio, Published: Apr 02, 2026, Unreviewed, MinIO is Vulnerable to SSE Metadata Injection via Replication Headers in github.com/minio/minio


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b32075d037904ab28a0f44e257b35a17</guid>
<pubDate>Thu, 02 Apr 2026 17:08:31 -0400</pubDate>
<title>GO-2026-4894</title>
<link>https://pkg.go.dev/vuln/GO-2026-4894</link>
<description><![CDATA[CVE-2026-32241, GHSA-vchx-5pr6-ffx2, github.com/flannel-io/flannel, Published: Apr 02, 2026, Unreviewed, Flannel has cross-node remote code execution via extension backend BackendData injection in github.com/flannel-io/flannel


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ee469caecb882821f1e51c9f8e529196</guid>
<pubDate>Thu, 02 Apr 2026 17:08:25 -0400</pubDate>
<title>GO-2026-4893</title>
<link>https://pkg.go.dev/vuln/GO-2026-4893</link>
<description><![CDATA[CVE-2026-33433, GHSA-qr99-7898-vr7c, github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more, Published: Apr 02, 2026, Unreviewed, Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField in github.com/traefik/traefik


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">56e01fcfc405fe14c76273235b1e3d73</guid>
<pubDate>Thu, 02 Apr 2026 17:08:19 -0400</pubDate>
<title>GO-2026-4892</title>
<link>https://pkg.go.dev/vuln/GO-2026-4892</link>
<description><![CDATA[CVE-2026-29180, GHSA-m2h6-4xpq-qw3m, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, A Fleet team maintainer can transfer hosts from any team via missing source team authorization in github.com/fleetdm/fleet


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e17dcd189c61413a9e7fba628025ea1b</guid>
<pubDate>Thu, 02 Apr 2026 17:08:11 -0400</pubDate>
<title>GO-2026-4891</title>
<link>https://pkg.go.dev/vuln/GO-2026-4891</link>
<description><![CDATA[CVE-2026-34041, GHSA-xmgr-9pqc-h5vw, github.com/nektos/act, Published: Apr 02, 2026, Unreviewed, act: Unrestricted set-env and add-path command processing enables environment injection in github.com/nektos/act


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">53095b98211ee05c0d10b2851d643e02</guid>
<pubDate>Thu, 02 Apr 2026 17:08:08 -0400</pubDate>
<title>GO-2026-4890</title>
<link>https://pkg.go.dev/vuln/GO-2026-4890</link>
<description><![CDATA[CVE-2026-34042, GHSA-x34h-54cw-9825, github.com/nektos/act, Published: Apr 02, 2026, Unreviewed, act: actions/cache server allows malicious cache injection in github.com/nektos/act


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e74030968abbaf2b3e36ec1e3d4340e6</guid>
<pubDate>Thu, 02 Apr 2026 17:07:59 -0400</pubDate>
<title>GO-2026-4889</title>
<link>https://pkg.go.dev/vuln/GO-2026-4889</link>
<description><![CDATA[CVE-2026-26061, GHSA-99hj-44vg-hfcp, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet's unbounded request body read allows remote Denial of Service in github.com/fleetdm/fleet.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/fleetdm/fleet/v4 before v4.43.5-0.20260113202849-bbc1aef2987d.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f9a4f3d49a63bb349643cfc9fd1ad2f7</guid>
<pubDate>Thu, 02 Apr 2026 17:07:57 -0400</pubDate>
<title>GO-2026-4888</title>
<link>https://pkg.go.dev/vuln/GO-2026-4888</link>
<description><![CDATA[CVE-2026-26060, GHSA-3458-r943-hmx4, github.com/fleetdm/fleet/v4, Published: Apr 02, 2026, Unreviewed, Fleet: Password reset tokens remain valid after password change for 24 hours in github.com/fleetdm/fleet.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/fleetdm/fleet/v4 before v4.43.5-0.20260113202849-bbc1aef2987d.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">bf901050152fec7ac11df836b2cc036e</guid>
<pubDate>Thu, 02 Apr 2026 17:07:48 -0400</pubDate>
<title>GO-2026-4887</title>
<link>https://pkg.go.dev/vuln/GO-2026-4887</link>
<description><![CDATA[CVE-2026-34040, GHSA-x744-4wpc-v9h2, github.com/docker/docker, github.com/moby/moby, and 1 more, Published: Apr 02, 2026, Unreviewed, Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f06f2a057247294dd660b275a44bed1f</guid>
<pubDate>Tue, 07 Apr 2026 12:25:01 -0400</pubDate>
<title>GO-2026-4886</title>
<link>https://pkg.go.dev/vuln/GO-2026-4886</link>
<description><![CDATA[CVE-2026-33743, GHSA-vg76-xmhg-j5x3, github.com/lxc/incus, github.com/lxc/incus/v6, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4885">GO-2026-4885</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33711, GHSA-q9vp-3wcg-8p4x
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/lxc/incus, github.com/lxc/incus/v6
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Incus vulnerable to local privilege escalation through VM screenshot path in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4884">GO-2026-4884</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33945, GHSA-q4q8-7f2j-9h9f
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/lxc/incus, github.com/lxc/incus/v6
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Incus has an abitrary file write through its systemd-creds options in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4883">GO-2026-4883</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33997, GHSA-pxq6-2prw-chj9
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/docker/docker, github.com/moby/moby, and 1 more
        
      </li>
      <li class="go-textSubtle">Published: Apr 02, 2026, Unreviewed, Moby has an Off-by-one error in its plugin privilege validation in github.com/docker/docker


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ae977911aa5f575477b3c49098a2c041</guid>
<pubDate>Tue, 07 Apr 2026 12:24:55 -0400</pubDate>
<title>GO-2026-4882</title>
<link>https://pkg.go.dev/vuln/GO-2026-4882</link>
<description><![CDATA[CVE-2026-33542, GHSA-p8mm-23gg-jc9r, github.com/lxc/incus, github.com/lxc/incus/v6, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4881">GO-2026-4881</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33897, GHSA-83xr-5xxr-mh92
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/lxc/incus, github.com/lxc/incus/v6
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Incus vulnerable to arbitrary file read and write through pongo templates in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4880">GO-2026-4880</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-32695, GHSA-67jx-r9pv-98rj
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more
        
      </li>
      <li class="go-textSubtle">Published: Apr 02, 2026, Unreviewed, Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass in github.com/traefik/traefik


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3405ca974c6964384d2b93aa44c2b1c4</guid>
<pubDate>Tue, 07 Apr 2026 12:24:49 -0400</pubDate>
<title>GO-2026-4879</title>
<link>https://pkg.go.dev/vuln/GO-2026-4879</link>
<description><![CDATA[CVE-2026-33898, GHSA-453r-g2pg-cxxq, github.com/lxc/incus, github.com/lxc/incus/v6, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Local Incus UI web server vulnerable to nuthentication bypass in github.com/lxc/incus</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4876">GO-2026-4876</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          GHSA-prh4-vhfh-24mj
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/goharbor/harbor
        
      </li>
      <li class="go-textSubtle">Published: Apr 02, 2026, Unreviewed, Harbor: LDAP password and OIDC secret are not redacted in the audit log in github.com/goharbor/harbor


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e2196dd38971c25afd34ca51d43b8d3e</guid>
<pubDate>Thu, 02 Apr 2026 17:07:22 -0400</pubDate>
<title>GO-2026-4875</title>
<link>https://pkg.go.dev/vuln/GO-2026-4875</link>
<description><![CDATA[CVE-2026-33903, GHSA-f2f3-9cx3-wcmf, github.com/ellanetworks/core, Published: Apr 02, 2026, Unreviewed, Ella Core panics when processing a crafted NGAP LocationReport message in github.com/ellanetworks/core


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d2934e9c7bcd5679f1f08fc7861989b8</guid>
<pubDate>Thu, 02 Apr 2026 17:07:20 -0400</pubDate>
<title>GO-2026-4874</title>
<link>https://pkg.go.dev/vuln/GO-2026-4874</link>
<description><![CDATA[CVE-2026-33904, GHSA-9h59-p45g-445h, github.com/ellanetworks/core, Published: Apr 02, 2026, Unreviewed, Ella Core has a Denial of Service via SCTP connection cleanup deadlock in github.com/ellanetworks/core


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">beba8c6d165e22f81c13117d0aa278a5</guid>
<pubDate>Thu, 02 Apr 2026 17:07:13 -0400</pubDate>
<title>GO-2026-4873</title>
<link>https://pkg.go.dev/vuln/GO-2026-4873</link>
<description><![CDATA[CVE-2026-33906, GHSA-87j9-m7x6-hvw2, github.com/ellanetworks/core, Published: Apr 02, 2026, Unreviewed, Ella Core has Privilege Escalation via Database Restore by NetworkManager role in github.com/ellanetworks/core


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8b0aa22b2365ecba020e91d05583af18</guid>
<pubDate>Thu, 02 Apr 2026 17:07:10 -0400</pubDate>
<title>GO-2026-4872</title>
<link>https://pkg.go.dev/vuln/GO-2026-4872</link>
<description><![CDATA[CVE-2026-33907, GHSA-55q8-2gwx-29pc, github.com/ellanetworks/core, Published: Apr 02, 2026, Unreviewed, Ella Core Panics during NAS Authentication Response/Failure with missing IEs in github.com/ellanetworks/core


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">456110efeb10565bff220dd93c07ea61</guid>
<pubDate>Tue, 07 Apr 2026 21:37:42 -0400</pubDate>
<title>GO-2026-4871
        
        
  
  
    standard library
  

      
      
        
  
  
    
    
      
        
          CVE-2026-27140
        
      
      Affects:
       
          cmd/go
        
      
      Published: Apr 07, 2026
      
      
      
    

    
      SWIG file names containing &#039;cgo&#039; and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
    
  

      
    
      
        
          GO-2026-4870
        
        
  
  
    standard library
  

      ...</title>
<link>https://pkg.go.dev/vuln/GO-2026-4871</link>
<description><![CDATA[GHSA-g9ww-x58f-9g6m, github.com/edgelesssys/contrast, Published: Apr 02, 2026, Unreviewed, Contrast BadAML injection allows arbitrary code execution in github.com/edgelesssys/contrast


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">eee7af0b6015a787e0c9a528142cf5b1</guid>
<pubDate>Thu, 02 Apr 2026 17:06:52 -0400</pubDate>
<title>GO-2026-4862</title>
<link>https://pkg.go.dev/vuln/GO-2026-4862</link>
<description><![CDATA[CVE-2026-33758, GHSA-cpj3-3r2f-xj59, github.com/openbao/openbao, Published: Mar 26, 2026, Unreviewed, OpenBao has Reflected XSS in its OIDC authentication error message in github.com/openbao/openbao


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7efd084579784b94634735a089de6d71</guid>
<pubDate>Thu, 26 Mar 2026 18:05:33 -0400</pubDate>
<title>GO-2026-4861</title>
<link>https://pkg.go.dev/vuln/GO-2026-4861</link>
<description><![CDATA[CVE-2019-8400, GHSA-7v6r-w4r6-mhch, github.com/ory/hydra, Published: Mar 26, 2026, Unreviewed, Hydra has Reflected XSS via error_hint parameter in github.com/ory/hydra.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/ory/hydra before v1.4.8.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b8f4fe3411207cffe9252261ef8f9b56</guid>
<pubDate>Thu, 26 Mar 2026 18:05:25 -0400</pubDate>
<title>GO-2026-4860</title>
<link>https://pkg.go.dev/vuln/GO-2026-4860</link>
<description><![CDATA[CVE-2026-33757, GHSA-7q7g-x6vg-xpc3, github.com/openbao/openbao, Published: Mar 26, 2026, Unreviewed, OpenBao lacks user confirmation for OIDC direct callback mode in github.com/openbao/openbao


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">562433709625ae432bee951041679290</guid>
<pubDate>Fri, 27 Mar 2026 21:45:31 -0400</pubDate>
<title>GO-2026-4859</title>
<link>https://pkg.go.dev/vuln/GO-2026-4859</link>
<description><![CDATA[CVE-2026-33748, GHSA-4vrq-3vrq-g6gg, github.com/moby/buildkit, Published: Mar 27, 2026</li>
      
      
      
    </ul>

    
      <p>BuildKit Git URL subdir component can cause access to restricted files in github.com/moby/buildkit</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4858">GO-2026-4858</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33747, GHSA-4c29-8rgm-jvjj
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/moby/buildkit
        
      </li>
      <li class="go-textSubtle">Published: Mar 27, 2026</li>
      
      
      
    </ul>

    
      <p>BuildKit's Malicious frontend can cause file escape outside of storage root in github.com/moby/buildkit</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4857">GO-2026-4857</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33729, GHSA-h6c8-cww8-35hf
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/openfga/openfga
        
      </li>
      <li class="go-textSubtle">Published: Mar 26, 2026, Unreviewed, OpenFGA has an Authorization Bypass through cached keys in github.com/openfga/openfga


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d1c1cebe7dcd2f119fb66ffad78f7357</guid>
<pubDate>Thu, 26 Mar 2026 18:05:13 -0400</pubDate>
<title>GO-2026-4856</title>
<link>https://pkg.go.dev/vuln/GO-2026-4856</link>
<description><![CDATA[CVE-2026-33726, GHSA-hxv8-4j4r-cqgv, github.com/cilium/cilium, Published: Mar 26, 2026, Unreviewed, Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic in github.com/cilium/cilium


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">52bd79da21f649476ef41cb436314f58</guid>
<pubDate>Thu, 26 Mar 2026 18:05:10 -0400</pubDate>
<title>GO-2026-4855</title>
<link>https://pkg.go.dev/vuln/GO-2026-4855</link>
<description><![CDATA[GHSA-2pv8-4c52-mf8j, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7538cccd9b899053175e7fd519cb0ff8</guid>
<pubDate>Thu, 26 Mar 2026 18:05:02 -0400</pubDate>
<title>GO-2026-4854</title>
<link>https://pkg.go.dev/vuln/GO-2026-4854</link>
<description><![CDATA[CVE-2026-24516, GHSA-fh3m-562m-w4f6, github.com/digitalocean/droplet-agent, Published: Mar 26, 2026, Unreviewed, DigitalOcean Droplet Agent: Command Injection via Metadata Service Endpoint in github.com/digitalocean/droplet-agent


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">973fa190f7ee478a11d0630a2f73ab6e</guid>
<pubDate>Thu, 26 Mar 2026 18:04:53 -0400</pubDate>
<title>GO-2026-4853</title>
<link>https://pkg.go.dev/vuln/GO-2026-4853</link>
<description><![CDATA[CVE-2026-33678, GHSA-jfmm-mjcp-8wq2, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8392c924a749380bf5080de156a9232f</guid>
<pubDate>Thu, 26 Mar 2026 18:04:49 -0400</pubDate>
<title>GO-2026-4852</title>
<link>https://pkg.go.dev/vuln/GO-2026-4852</link>
<description><![CDATA[CVE-2026-33679, GHSA-g9xj-752q-xh63, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3f69880f86ee6c4b23c1b67a98b1719a</guid>
<pubDate>Thu, 26 Mar 2026 18:04:41 -0400</pubDate>
<title>GO-2026-4851</title>
<link>https://pkg.go.dev/vuln/GO-2026-4851</link>
<description><![CDATA[CVE-2026-33675, GHSA-g66v-54v9-52pr, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">39735c34af7af5a0533124d354ccbe83</guid>
<pubDate>Thu, 26 Mar 2026 18:04:35 -0400</pubDate>
<title>GO-2026-4850</title>
<link>https://pkg.go.dev/vuln/GO-2026-4850</link>
<description><![CDATA[CVE-2026-33700, GHSA-f95f-77jx-fcjc, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0388195d61b4f6241d93145c85a4fdf0</guid>
<pubDate>Thu, 26 Mar 2026 18:04:32 -0400</pubDate>
<title>GO-2026-4849</title>
<link>https://pkg.go.dev/vuln/GO-2026-4849</link>
<description><![CDATA[CVE-2026-33668, GHSA-94xm-jj8x-3cr4, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0fd7d3252b31642a0b8fce012a0e3569</guid>
<pubDate>Thu, 26 Mar 2026 18:04:24 -0400</pubDate>
<title>GO-2026-4848</title>
<link>https://pkg.go.dev/vuln/GO-2026-4848</link>
<description><![CDATA[CVE-2026-33680, GHSA-8hp8-9fhr-pfm9, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.2.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b86d02d0fd3ecd7c35a3cc2c640ea7a6</guid>
<pubDate>Thu, 26 Mar 2026 18:04:21 -0400</pubDate>
<title>GO-2026-4847</title>
<link>https://pkg.go.dev/vuln/GO-2026-4847</link>
<description><![CDATA[CVE-2026-33676, GHSA-8cmm-j6c4-rr8v, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">2a3385409f42adb4907cd1b064ecb405</guid>
<pubDate>Thu, 26 Mar 2026 18:04:15 -0400</pubDate>
<title>GO-2026-4846</title>
<link>https://pkg.go.dev/vuln/GO-2026-4846</link>
<description><![CDATA[CVE-2026-33677, GHSA-7c2g-p23p-4jg3, code.vikunja.io/api, Published: Mar 26, 2026, Unreviewed, Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.1.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ba07c908be3c7ccdb8c73f368a6dc08b</guid>
<pubDate>Thu, 26 Mar 2026 18:04:10 -0400</pubDate>
<title>GO-2026-4845</title>
<link>https://pkg.go.dev/vuln/GO-2026-4845</link>
<description><![CDATA[CVE-2026-4404, GHSA-hj7x-hmf2-hc2p, github.com/goharbor/harbor, Published: Mar 26, 2026, Unreviewed, Harbor allows the use of the default password for web UI login in github.com/goharbor/harbor


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">6801c5871612db24ca85f549568ec955</guid>
<pubDate>Thu, 26 Mar 2026 18:04:03 -0400</pubDate>
<title>GO-2026-4844</title>
<link>https://pkg.go.dev/vuln/GO-2026-4844</link>
<description><![CDATA[CVE-2026-33529, GHSA-7pq3-326h-f8q9, github.com/tobychui/zoraxy, Published: Mar 26, 2026, Unreviewed, Zoraxy: Authenticated Path Traversal in Config Import leads to RCE in github.com/tobychui/zoraxy


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3254f8cef840d42568d9447cad8e5fa8</guid>
<pubDate>Thu, 26 Mar 2026 18:03:58 -0400</pubDate>
<title>GO-2026-4843</title>
<link>https://pkg.go.dev/vuln/GO-2026-4843</link>
<description><![CDATA[CVE-2026-33670, GHSA-xmw9-6r43-x9ww, github.com/siyuan-note/siyuan/kernel, Published: Mar 26, 2026, Unreviewed, SiYuan has directory traversal within its publishing service in github.com/siyuan-note/siyuan/kernel


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">00ff47519f30c1235e5f5eff235657b5</guid>
<pubDate>Thu, 26 Mar 2026 18:03:49 -0400</pubDate>
<title>GO-2026-4842</title>
<link>https://pkg.go.dev/vuln/GO-2026-4842</link>
<description><![CDATA[CVE-2026-33669, GHSA-34xj-66v3-6j83, github.com/siyuan-note/siyuan/kernel, Published: Mar 26, 2026, Unreviewed, SiYuan has Arbitrary Document Reading within the Publishing Service in github.com/siyuan-note/siyuan/kernel


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">19e9dc6af8f088ebf1589bf57b1a029e</guid>
<pubDate>Thu, 26 Mar 2026 18:03:45 -0400</pubDate>
<title>GO-2026-4841</title>
<link>https://pkg.go.dev/vuln/GO-2026-4841</link>
<description><![CDATA[CVE-2026-27889, GHSA-pq2q-rcw4-3hr6, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a79763371316b2e5cb083ffdb46012cf</guid>
<pubDate>Thu, 26 Mar 2026 18:03:38 -0400</pubDate>
<title>GO-2026-4838</title>
<link>https://pkg.go.dev/vuln/GO-2026-4838</link>
<description><![CDATA[CVE-2026-33638, GHSA-m983-7426-5hrj, github.com/lin-snow/ech0, Published: Mar 26, 2026, Unreviewed, Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint in github.com/lin-snow/ech0


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e0d614e1fae37b5d570d37c33f6fc4e3</guid>
<pubDate>Thu, 26 Mar 2026 18:03:33 -0400</pubDate>
<title>GO-2026-4837</title>
<link>https://pkg.go.dev/vuln/GO-2026-4837</link>
<description><![CDATA[CVE-2026-33218, GHSA-vprv-35vv-q339, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">db7428da7fb59ce220bb51ae0d4d4b27</guid>
<pubDate>Thu, 26 Mar 2026 18:03:24 -0400</pubDate>
<title>GO-2026-4836</title>
<link>https://pkg.go.dev/vuln/GO-2026-4836</link>
<description><![CDATA[CVE-2026-33216, GHSA-v722-jcv5-w7mc, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS has MQTT plaintext password disclosure in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">509bb61271f480fb3870b482c018adf9</guid>
<pubDate>Thu, 26 Mar 2026 18:03:21 -0400</pubDate>
<title>GO-2026-4835</title>
<link>https://pkg.go.dev/vuln/GO-2026-4835</link>
<description><![CDATA[CVE-2026-33223, GHSA-pwx7-fx9r-hr4h, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8722315870185c05ab6aa6f596ad0abe</guid>
<pubDate>Thu, 26 Mar 2026 18:03:12 -0400</pubDate>
<title>GO-2026-4834</title>
<link>https://pkg.go.dev/vuln/GO-2026-4834</link>
<description><![CDATA[CVE-2026-33217, GHSA-jxxm-27vp-c3m5, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS allows MQTT clients to bypass ACL checks in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">9e322ce22102c10ba13ee46439cbf87b</guid>
<pubDate>Thu, 26 Mar 2026 18:03:11 -0400</pubDate>
<title>GO-2026-4833</title>
<link>https://pkg.go.dev/vuln/GO-2026-4833</link>
<description><![CDATA[CVE-2026-33215, GHSA-fcjp-h8cc-6879, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS is vulnerable to MQTT hijacking via Client ID in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e55a0cfc995cdc7492d032704a69746a</guid>
<pubDate>Thu, 26 Mar 2026 18:03:00 -0400</pubDate>
<title>GO-2026-4832</title>
<link>https://pkg.go.dev/vuln/GO-2026-4832</link>
<description><![CDATA[CVE-2026-33222, GHSA-9983-vrx2-fg9c, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS JetStream has an authorization bypass through its Management API in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">78225fbaaf6f7c8b055a25b02279908e</guid>
<pubDate>Thu, 26 Mar 2026 18:02:56 -0400</pubDate>
<title>GO-2026-4831</title>
<link>https://pkg.go.dev/vuln/GO-2026-4831</link>
<description><![CDATA[CVE-2026-33219, GHSA-8r68-gvr4-jh7j, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS is vulnerable to pre-auth DoS through WebSockets client service in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8e3930b1274125e21b1f84d9a0878556</guid>
<pubDate>Thu, 26 Mar 2026 18:02:47 -0400</pubDate>
<title>GO-2026-4830</title>
<link>https://pkg.go.dev/vuln/GO-2026-4830</link>
<description><![CDATA[CVE-2026-33246, GHSA-55h8-8g96-x4hj, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1bc3573a7d8a68a7c15c9cd55dac614a</guid>
<pubDate>Thu, 26 Mar 2026 18:02:47 -0400</pubDate>
<title>GO-2026-4829</title>
<link>https://pkg.go.dev/vuln/GO-2026-4829</link>
<description><![CDATA[CVE-2026-29785, GHSA-52jh-2xxh-pwh6, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">64efaeef21dc3e93e709883f879af385</guid>
<pubDate>Thu, 26 Mar 2026 18:02:37 -0400</pubDate>
<title>GO-2026-4828</title>
<link>https://pkg.go.dev/vuln/GO-2026-4828</link>
<description><![CDATA[CVE-2026-33248, GHSA-3f24-pcvm-5jqc, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">92179711f315036523f0bc2ecb850a46</guid>
<pubDate>Thu, 26 Mar 2026 18:02:33 -0400</pubDate>
<title>GO-2026-4827</title>
<link>https://pkg.go.dev/vuln/GO-2026-4827</link>
<description><![CDATA[CVE-2026-33247, GHSA-x6g4-f6q3-fqvv, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS credentials are exposed in monitoring port via command-line argv in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">6c9d872205bfb3af869acb5301be74c3</guid>
<pubDate>Thu, 26 Mar 2026 18:02:24 -0400</pubDate>
<title>GO-2026-4826</title>
<link>https://pkg.go.dev/vuln/GO-2026-4826</link>
<description><![CDATA[CVE-2026-33249, GHSA-8m2x-3m6q-6w8j, github.com/nats-io/nats-server, github.com/nats-io/nats-server/v2, Published: Mar 26, 2026, Unreviewed, NATS: Message tracing can be redirected to arbitrary subject in github.com/nats-io/nats-server


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b890f9564a11e3ebb278176f9a5fa9fb</guid>
<pubDate>Thu, 26 Mar 2026 18:02:20 -0400</pubDate>
<title>GO-2026-4825</title>
<link>https://pkg.go.dev/vuln/GO-2026-4825</link>
<description><![CDATA[CVE-2026-33619, GHSA-xqq2-4j46-vwp7, github.com/pinchtab/pinchtab, Published: Mar 26, 2026, Unreviewed, PinchTab has Unauthenticated Blind SSRF in Task Scheduler via Unvalidated callbackUrl in github.com/pinchtab/pinchtab


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d33a894b6d5ca41592043ac24bc4d79e</guid>
<pubDate>Thu, 26 Mar 2026 18:02:17 -0400</pubDate>
<title>GO-2026-4824</title>
<link>https://pkg.go.dev/vuln/GO-2026-4824</link>
<description><![CDATA[CVE-2026-33622, GHSA-w5pc-m664-r62v, github.com/pinchtab/pinchtab, Published: Mar 26, 2026, Unreviewed, A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution in github.com/pinchtab/pinchtab


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8ae5248b733a9bf222834230085d95eb</guid>
<pubDate>Thu, 26 Mar 2026 18:02:09 -0400</pubDate>
<title>GO-2026-4823</title>
<link>https://pkg.go.dev/vuln/GO-2026-4823</link>
<description><![CDATA[CVE-2026-33623, GHSA-p8mm-644p-phmh, github.com/pinchtab/pinchtab, Published: Mar 26, 2026, Unreviewed, PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution in github.com/pinchtab/pinchtab


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e2438b70493d37d4c485a237f223e52f</guid>
<pubDate>Thu, 26 Mar 2026 18:02:00 -0400</pubDate>
<title>GO-2026-4822</title>
<link>https://pkg.go.dev/vuln/GO-2026-4822</link>
<description><![CDATA[CVE-2026-33620, GHSA-mrqc-3276-74f8, github.com/pinchtab/pinchtab, Published: Mar 26, 2026, Unreviewed, PinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and Intermediary Systems in github.com/pinchtab/pinchtab


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">60fa912514813eec05bc8cdc0b0f0025</guid>
<pubDate>Thu, 26 Mar 2026 18:01:53 -0400</pubDate>
<title>GO-2026-4821</title>
<link>https://pkg.go.dev/vuln/GO-2026-4821</link>
<description><![CDATA[CVE-2026-33621, GHSA-j65m-hv65-r264, github.com/pinchtab/pinchtab, Published: Mar 26, 2026, Unreviewed, PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token in github.com/pinchtab/pinchtab


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8bcad963bb0b66c1f8a1488a294e7ccd</guid>
<pubDate>Thu, 26 Mar 2026 18:01:51 -0400</pubDate>
<title>GO-2026-4820</title>
<link>https://pkg.go.dev/vuln/GO-2026-4820</link>
<description><![CDATA[GHSA-7789-65hx-f26w, github.com/gtsteffaniak/filebrowser/backend, Published: Mar 26, 2026, Unreviewed, FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c085968ad4f2a104ddafe7e5a56a1be9</guid>
<pubDate>Thu, 26 Mar 2026 18:01:44 -0400</pubDate>
<title>GO-2026-4818</title>
<link>https://pkg.go.dev/vuln/GO-2026-4818</link>
<description><![CDATA[CVE-2026-33525, GHSA-gmfg-3v4q-9qr4, github.com/authelia/authelia, github.com/authelia/authelia/v4, Published: Mar 26, 2026, Unreviewed, Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting in github.com/authelia/authelia


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d33a8a1a3bc6fbc77c6488c7e89159fc</guid>
<pubDate>Thu, 26 Mar 2026 18:01:37 -0400</pubDate>
<title>GO-2026-4817</title>
<link>https://pkg.go.dev/vuln/GO-2026-4817</link>
<description><![CDATA[CVE-2026-33528, GHSA-4753-cmc8-8j9v, github.com/yusing/godoxy, Published: Mar 26, 2026, Unreviewed, GoDoxy has a Path Traversal Vulnerability in its File API in github.com/yusing/godoxy


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">307fc03f449adb2e04c22fbd720c1c20</guid>
<pubDate>Thu, 26 Mar 2026 18:01:29 -0400</pubDate>
<title>GO-2026-4816</title>
<link>https://pkg.go.dev/vuln/GO-2026-4816</link>
<description><![CDATA[CVE-2026-3864, GHSA-2mjq-54qg-7w6j, github.com/kubernetes-csi/csi-driver-nfs, Published: Mar 26, 2026, Unreviewed, NFS CSI driver for Kubernetes is Vulnerable to Path Traversal through Volume Identifier Parameter in github.com/kubernetes-csi/csi-driver-nfs


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">599b80454eabd2e5a932ac64c607357e</guid>
<pubDate>Wed, 25 Mar 2026 17:05:25 -0400</pubDate>
<title>GO-2026-4815</title>
<link>https://pkg.go.dev/vuln/GO-2026-4815</link>
<description><![CDATA[CVE-2026-33809, GHSA-44p7-9xx4-hf2g, golang.org/x/image, Published: Mar 25, 2026</li>
      
        <li class="go-textSubtle">Modified: Apr 06, 2026</li>
      
      
      
    </ul>

    
      <p>A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4814">GO-2026-4814</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-30886, GHSA-f35r-v9x5-r8mc
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/QuantumNous/new-api
        
      </li>
      <li class="go-textSubtle">Published: Mar 26, 2026, Unreviewed, New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check in github.com/QuantumNous/new-api


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d9e5fc41bc9c7530dbfebfbbcb9347e5</guid>
<pubDate>Thu, 26 Mar 2026 18:01:28 -0400</pubDate>
<title>GO-2026-4813</title>
<link>https://pkg.go.dev/vuln/GO-2026-4813</link>
<description><![CDATA[CVE-2026-32879, GHSA-5353-f8fq-65vc, github.com/QuantumNous/new-api, Published: Mar 26, 2026, Unreviewed, New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure in github.com/QuantumNous/new-api


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">191eb913cbe080ddb154897e3327bb03</guid>
<pubDate>Thu, 26 Mar 2026 18:01:23 -0400</pubDate>
<title>GO-2026-4812</title>
<link>https://pkg.go.dev/vuln/GO-2026-4812</link>
<description><![CDATA[CVE-2026-26304, GHSA-4pmx-622h-x359, github.com/mattermost/mattermost-plugin-playbooks, Published: Mar 23, 2026, Unreviewed, Mattermost fails to verify run_create permission for empty playbookId in github.com/mattermost/mattermost-plugin-playbooks


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">fc0aff504f3e0d73ce5d164064135ce0</guid>
<pubDate>Mon, 23 Mar 2026 20:02:25 -0400</pubDate>
<title>GO-2026-4811</title>
<link>https://pkg.go.dev/vuln/GO-2026-4811</link>
<description><![CDATA[CVE-2026-33474, GHSA-wc83-79hj-hpmq, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja Affected by DoS via Image Preview Generation in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api from v1.0.0-rc0 before v2.2.0.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">dbeda840b0f98b81ad3a7200ae507c53</guid>
<pubDate>Mon, 23 Mar 2026 20:02:23 -0400</pubDate>
<title>GO-2026-4810</title>
<link>https://pkg.go.dev/vuln/GO-2026-4810</link>
<description><![CDATA[CVE-2026-33495, GHSA-vhr5-ggp3-qq85, github.com/ory/oathkeeper, Published: Mar 23, 2026, Unreviewed, Ory Oathkeeper has an authentication bypass by usage of untrusted header in github.com/ory/oathkeeper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">31c596f532aee5dab29883345d8eb462</guid>
<pubDate>Mon, 23 Mar 2026 20:02:18 -0400</pubDate>
<title>GO-2026-4809</title>
<link>https://pkg.go.dev/vuln/GO-2026-4809</link>
<description><![CDATA[CVE-2026-33481, GHSA-rjcw-vg7j-m9rc, github.com/anchore/syft, Published: Mar 23, 2026, Unreviewed, Syft improper temporary file cleanup in github.com/anchore/syft


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">dbec630aa3c40e9d07a6415637890163</guid>
<pubDate>Tue, 07 Apr 2026 12:24:43 -0400</pubDate>
<title>GO-2026-4808</title>
<link>https://pkg.go.dev/vuln/GO-2026-4808</link>
<description><![CDATA[CVE-2026-33343, GHSA-rfx7-8w68-q57q, go.etcd.io/etcd, go.etcd.io/etcd/v3, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4807">GO-2026-4807</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33504, GHSA-r9w3-57w2-gch2
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/ory/hydra, github.com/ory/hydra/v2
        
      </li>
      <li class="go-textSubtle">Published: Mar 23, 2026, Unreviewed, Ory Hydra has a SQL injection via forged pagination tokens in github.com/ory/hydra


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0ff25bc07b77321da6c27e04e46da24a</guid>
<pubDate>Tue, 07 Apr 2026 12:24:38 -0400</pubDate>
<title>GO-2026-4806</title>
<link>https://pkg.go.dev/vuln/GO-2026-4806</link>
<description><![CDATA[CVE-2026-33413, GHSA-q8m4-xhhv-38mg, go.etcd.io/etcd, go.etcd.io/etcd/v3, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Authorization bypasses in multiple APIs in go.etcd.io/etcd</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4805">GO-2026-4805</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33473, GHSA-p747-qc5p-773r
        </li>
      
      <li class="go-textSubtle">Affects:
       
          code.vikunja.io/api
        
      </li>
      <li class="go-textSubtle">Published: Mar 23, 2026, Unreviewed, Vikunja has TOTP Reuse During Validity Window in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: .


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ae3a022f40f60e92cac529e5d836c1da</guid>
<pubDate>Mon, 23 Mar 2026 20:02:01 -0400</pubDate>
<title>GO-2026-4804</title>
<link>https://pkg.go.dev/vuln/GO-2026-4804</link>
<description><![CDATA[CVE-2026-33494, GHSA-p224-6x5r-fjpm, github.com/ory/oathkeeper, Published: Mar 23, 2026, Unreviewed, Ory Oathkeeper has a path traversal authorization bypass in github.com/ory/oathkeeper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">328c2091a3179a8063dfe5d0759aca99</guid>
<pubDate>Mon, 23 Mar 2026 20:01:51 -0400</pubDate>
<title>GO-2026-4803</title>
<link>https://pkg.go.dev/vuln/GO-2026-4803</link>
<description><![CDATA[CVE-2026-33419, GHSA-jv87-32hw-hh99, github.com/minio/minio, Published: Mar 23, 2026, Unreviewed, MinIO LDAP login brute-force via user enumeration and missing rate limit in github.com/minio/minio


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f5da4f055ae14ea4d6b36cc76ddba814</guid>
<pubDate>Mon, 23 Mar 2026 20:01:48 -0400</pubDate>
<title>GO-2026-4802</title>
<link>https://pkg.go.dev/vuln/GO-2026-4802</link>
<description><![CDATA[CVE-2026-33476, GHSA-hhgj-gg9h-rjp7, github.com/siyuan-note/siyuan/kernel, Published: Mar 23, 2026, Unreviewed, Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal in github.com/siyuan-note/siyuan/kernel


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1f7043ced7d20e433528c457a6421e7f</guid>
<pubDate>Mon, 23 Mar 2026 20:01:40 -0400</pubDate>
<title>GO-2026-4801</title>
<link>https://pkg.go.dev/vuln/GO-2026-4801</link>
<description><![CDATA[CVE-2026-33503, GHSA-hgx2-28f8-6g2r, github.com/ory/kratos, Published: Mar 23, 2026, Unreviewed, Ory Kratos has a SQL injection via forged pagination tokens in github.com/ory/kratos


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">348b6362597dd10f55c12f21a87ec76f</guid>
<pubDate>Mon, 23 Mar 2026 20:01:32 -0400</pubDate>
<title>GO-2026-4800</title>
<link>https://pkg.go.dev/vuln/GO-2026-4800</link>
<description><![CDATA[CVE-2026-33505, GHSA-c38g-mx2c-9wf2, github.com/ory/keto, Published: Mar 23, 2026, Unreviewed, Ory Keto has a SQL injection via forged pagination tokens in github.com/ory/keto


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d6dd7a8a5f94e2c93420f714916c5984</guid>
<pubDate>Mon, 23 Mar 2026 20:01:29 -0400</pubDate>
<title>GO-2026-4799</title>
<link>https://pkg.go.dev/vuln/GO-2026-4799</link>
<description><![CDATA[CVE-2026-33496, GHSA-4mq7-pvjg-xp2r, github.com/ory/oathkeeper, Published: Mar 23, 2026, Unreviewed, Ory Oathkeeper has an authentication bypass by cache key confusion in github.com/ory/oathkeeper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7294e87177270680c0263f0e2f14f7a9</guid>
<pubDate>Mon, 23 Mar 2026 20:01:19 -0400</pubDate>
<title>GO-2026-4798</title>
<link>https://pkg.go.dev/vuln/GO-2026-4798</link>
<description><![CDATA[CVE-2026-33316, GHSA-vq4q-79hh-q767, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement in code.vikunja.io/api


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1c39d72d6770173617c214860df342ee</guid>
<pubDate>Mon, 23 Mar 2026 20:01:16 -0400</pubDate>
<title>GO-2026-4797</title>
<link>https://pkg.go.dev/vuln/GO-2026-4797</link>
<description><![CDATA[CVE-2026-33313, GHSA-mr3j-p26x-72x4, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments in code.vikunja.io/api


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f5f49a17e2a67e51c45737b2596d99dd</guid>
<pubDate>Mon, 23 Mar 2026 20:01:08 -0400</pubDate>
<title>GO-2026-4796</title>
<link>https://pkg.go.dev/vuln/GO-2026-4796</link>
<description><![CDATA[CVE-2026-4342, GHSA-f53h-mxv9-cp98, k8s.io/ingress-nginx, Published: Mar 23, 2026, Unreviewed, ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">2a00d9d00b70bd22f392e521482dc112</guid>
<pubDate>Mon, 23 Mar 2026 20:01:07 -0400</pubDate>
<title>GO-2026-4795</title>
<link>https://pkg.go.dev/vuln/GO-2026-4795</link>
<description><![CDATA[CVE-2026-33312, GHSA-564f-wx8x-878h, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja read-only users can delete project background images via broken object-level authorization in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api before v2.2.0.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">139cbd3b08ac4a156c61eef86c1cc1ef</guid>
<pubDate>Mon, 23 Mar 2026 20:00:59 -0400</pubDate>
<title>GO-2026-4794</title>
<link>https://pkg.go.dev/vuln/GO-2026-4794</link>
<description><![CDATA[CVE-2026-33315, GHSA-47cr-f226-r4pq, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja has a 2FA Bypass via Caldav Basic Auth in code.vikunja.io/api


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c32c57e0c521c758a66e99b41b870c76</guid>
<pubDate>Mon, 23 Mar 2026 20:00:54 -0400</pubDate>
<title>GO-2026-4793</title>
<link>https://pkg.go.dev/vuln/GO-2026-4793</link>
<description><![CDATA[CVE-2026-32305, GHSA-wvvq-wgcr-9q48, github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more, Published: Mar 23, 2026, Unreviewed, Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config in github.com/traefik/traefik


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">84d1b69926ca200e999d2c959a54c5f1</guid>
<pubDate>Mon, 23 Mar 2026 20:00:43 -0400</pubDate>
<title>GO-2026-4792</title>
<link>https://pkg.go.dev/vuln/GO-2026-4792</link>
<description><![CDATA[CVE-2026-32595, GHSA-g3hg-j4jv-cwfr, github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more, Published: Mar 23, 2026, Unreviewed, Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration in github.com/traefik/traefik


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">610a2c99c2e2fdc35ad8eec657b2f5b7</guid>
<pubDate>Mon, 23 Mar 2026 20:00:40 -0400</pubDate>
<title>GO-2026-4791</title>
<link>https://pkg.go.dev/vuln/GO-2026-4791</link>
<description><![CDATA[CVE-2026-29794, GHSA-m547-hp4w-j6jx, code.vikunja.io/api, Published: Mar 23, 2026, Unreviewed, Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers in code.vikunja.io/api.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.vikunja.io/api from v0.8.0 before v2.2.0.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c28bfcfb7116eb7c5c3353e8c92ee1ee</guid>
<pubDate>Tue, 07 Apr 2026 12:24:29 -0400</pubDate>
<title>GO-2026-4790</title>
<link>https://pkg.go.dev/vuln/GO-2026-4790</link>
<description><![CDATA[CVE-2026-26931, GHSA-5vrw-qjxw-89r5, github.com/elastic/beats, github.com/elastic/beats/v7, Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service in github.com/elastic/beats</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4789">GO-2026-4789</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-26933, GHSA-27qj-9gvp-8rh9
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/elastic/beats, github.com/elastic/beats/v7
        
      </li>
      <li class="go-textSubtle">Published: Apr 07, 2026</li>
      
      
      
    </ul>

    
      <p>Packetbeat does not properly validate an array index in multiple protocol parser components in github.com/elastic/beats</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-4788">GO-2026-4788</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-33353, GHSA-xgxp-f695-6vrp
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/charmbracelet/soft-serve
        
      </li>
      <li class="go-textSubtle">Published: Mar 23, 2026, Unreviewed, In Soft Serve, an authenticated repo import can clone server-local private repositories in github.com/charmbracelet/soft-serve


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3694450fcdb210dbd2d6f156650ec384</guid>
<pubDate>Mon, 23 Mar 2026 20:00:26 -0400</pubDate>
<title>GO-2026-4786</title>
<link>https://pkg.go.dev/vuln/GO-2026-4786</link>
<description><![CDATA[CVE-2026-22545, GHSA-rv67-7w2g-7976, github.com/mattermost/mattermost-server, github.com/mattermost/mattermost-server/v5, and 2 more, Published: Mar 23, 2026, Unreviewed, Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://stephenslab.top">RssEverything</a> service</i></sub></p>


]]></description>
</item>

  </channel>
</rss>

