Search CVE reports


Toggle filters

31 – 40 of 1402 results


CVE-2025-29923

Medium priority
Needs evaluation

go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can...

1 affected package

golang-github-go-redis-redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-redis-redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-29786

Medium priority
Needs evaluation

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract...

1 affected package

golang-github-antonmedv-expr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antonmedv-expr Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2025-29785

Medium priority
Needs evaluation

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to...

1 affected package

golang-github-lucas-clemente-quic-go

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-lucas-clemente-quic-go Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2025-2938

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-2853

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-27614

Medium priority
Fixed

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g.,...

1 affected package

git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-27613

Medium priority
Fixed

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and...

1 affected package

git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-27144

Medium priority
Needs evaluation

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions...

1 affected package

golang-github-go-jose-go-jose

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-jose-go-jose Needs evaluation Not in release Not in release
Show less packages

CVE-2025-2443

Medium priority
Ignored

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-24358

Medium priority
Needs evaluation

gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation...

1 affected package

golang-github-gorilla-csrf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gorilla-csrf Needs evaluation Needs evaluation Needs evaluation
Show less packages