{"schema_version":1,"title":"stdlib (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 161 vulnerabilities in stdlib (Go): 0 in the last 7 days and 4 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-56853, was published on 13 August 2026.","url":"https://junglewise.ai/threats/technologies/go-stdlib","json_url":"https://junglewise.ai/threats/technologies/go-stdlib.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/go-stdlib","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":14,"all_time":161,"critical":3,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":44},"latest":[{"cve":"CVE-2026-56853","cvss":7.5,"epss":0.0057,"slug":"cve-2026-56853-go-http-2-timeout-bypass-in-unencrypted-connections","title":"Go HTTP/2 timeout bypass in unencrypted connections","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:22.093+00:00","url":"https://junglewise.ai/threats/cve-2026-56853-go-http-2-timeout-bypass-in-unencrypted-connections"},{"cve":"CVE-2026-46600","epss":0.0063,"slug":"cve-2026-46600-google-go-x-net-denial-of-service-in-dnsmessage-parsing","title":"Google Go x/net denial of service in dnsmessage parsing","severity":"info","exploited":false,"published_at":"2026-07-21T20:17:01.213+00:00","url":"https://junglewise.ai/threats/cve-2026-46600-google-go-x-net-denial-of-service-in-dnsmessage-parsing"},{"cve":"CVE-2026-42505","cvss":0,"epss":0.0041,"slug":"cve-2026-42505-go-crypto-tls-information-disclosure-in-encrypted-client-hello","title":"Go crypto/tls information disclosure in Encrypted Client Hello","severity":"info","exploited":false,"published_at":"2026-07-08T17:17:21.497+00:00","url":"https://junglewise.ai/threats/cve-2026-42505-go-crypto-tls-information-disclosure-in-encrypted-client-hello"},{"cve":"CVE-2026-39822","epss":0.0018,"slug":"cve-2026-39822-go-os-package-path-traversal-via-symlink-with-trailing-slash-in","title":"Go os package path traversal via symlink with trailing slash in os.Root","severity":"info","exploited":false,"published_at":"2026-07-08T17:17:21.31+00:00","url":"https://junglewise.ai/threats/cve-2026-39822-go-os-package-path-traversal-via-symlink-with-trailing-slash-in"},{"cve":"CVE-2026-42507","epss":0.0041,"slug":"cve-2026-42507-google-go-log-injection-in-net-textproto-package","title":"Google Go log injection in net/textproto package","severity":"info","exploited":false,"published_at":"2026-06-02T23:16:38.027+00:00","url":"https://junglewise.ai/threats/cve-2026-42507-google-go-log-injection-in-net-textproto-package"},{"cve":"CVE-2026-27145","cvss":0,"epss":0.0059,"slug":"cve-2026-27145-google-go-cpu-denial-of-service-in-crypto-x509-verifyhostname","title":"Google Go CPU denial of service in crypto/x509 VerifyHostname","severity":"info","exploited":false,"published_at":"2026-06-02T23:16:35.57+00:00","url":"https://junglewise.ai/threats/cve-2026-27145-google-go-cpu-denial-of-service-in-crypto-x509-verifyhostname"},{"cve":"CVE-2026-39821","cvss":9.6,"epss":0.0069,"slug":"cve-2026-39821-go-x-net-idna-privilege-escalation-via-punycode-decoding","title":"Go x/net idna privilege escalation via Punycode decoding","severity":"critical","exploited":false,"published_at":"2026-05-22T16:16:20.41+00:00","url":"https://junglewise.ai/threats/cve-2026-39821-go-x-net-idna-privilege-escalation-via-punycode-decoding"},{"cve":"CVE-2026-42499","cvss":7.5,"epss":0.008,"slug":"cve-2026-42499-google-go-net-mail-denial-of-service-in-consumephrase","title":"Google Go net/mail denial of service in consumePhrase","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:44.54+00:00","url":"https://junglewise.ai/threats/cve-2026-42499-google-go-net-mail-denial-of-service-in-consumephrase"},{"cve":"CVE-2026-39836","cvss":7.5,"epss":0.0062,"slug":"cve-2026-39836-google-go-denial-of-service-in-net-package-on-windows","title":"Google Go Denial of Service in net Package on Windows","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:43.593+00:00","url":"https://junglewise.ai/threats/cve-2026-39836-google-go-denial-of-service-in-net-package-on-windows"},{"cve":"CVE-2026-39826","cvss":6.1,"epss":0.0039,"slug":"cve-2026-39826-google-go-html-template-xss-via-script-type-attribute-bypass","title":"Google Go html/template XSS via script type attribute bypass","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:43.49+00:00","url":"https://junglewise.ai/threats/cve-2026-39826-google-go-html-template-xss-via-script-type-attribute-bypass"},{"cve":"CVE-2026-39825","cvss":5.3,"epss":0.0041,"slug":"cve-2026-39825-go-reverseproxy-parameter-smuggling-via-query-limit-mismatch","title":"Go ReverseProxy parameter smuggling via query limit mismatch","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:43.39+00:00","url":"https://junglewise.ai/threats/cve-2026-39825-go-reverseproxy-parameter-smuggling-via-query-limit-mismatch"},{"cve":"CVE-2026-39823","cvss":6.1,"epss":0.0033,"slug":"cve-2026-39823-go-html-template-xss-via-improper-escaping-in-meta-tags","title":"Go html/template XSS via improper escaping in meta tags","severity":"medium","exploited":false,"published_at":"2026-05-07T20:16:43.29+00:00","url":"https://junglewise.ai/threats/cve-2026-39823-go-html-template-xss-via-improper-escaping-in-meta-tags"},{"cve":"CVE-2026-39820","cvss":7.5,"epss":0.0087,"slug":"cve-2026-39820-go-net-mail-denial-of-service-in-email-and-date-parsing","title":"Go net/mail denial of service in email and date parsing","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:43.187+00:00","url":"https://junglewise.ai/threats/cve-2026-39820-go-net-mail-denial-of-service-in-email-and-date-parsing"},{"cve":"CVE-2026-33814","cvss":7.5,"epss":0.0078,"slug":"cve-2026-33814-go-net-http-infinite-loop-in-http-2-settings-frame-processing","title":"Go net/http infinite loop in HTTP/2 SETTINGS frame processing","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:42.88+00:00","url":"https://junglewise.ai/threats/cve-2026-33814-go-net-http-infinite-loop-in-http-2-settings-frame-processing"},{"cve":"CVE-2026-33811","cvss":7.5,"epss":0.0088,"slug":"cve-2026-33811-go-net-package-double-free-in-cgo-dns-resolver","title":"Go net package double-free in cgo DNS resolver","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:42.77+00:00","url":"https://junglewise.ai/threats/cve-2026-33811-go-net-package-double-free-in-cgo-dns-resolver"},{"cve":"CVE-2026-33810","cvss":8.2,"epss":0.0034,"slug":"cve-2026-33810-google-go-crypto-x509-improper-dns-constraint-validation","title":"Google Go crypto/x509 improper DNS constraint validation","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.95+00:00","url":"https://junglewise.ai/threats/cve-2026-33810-google-go-crypto-x509-improper-dns-constraint-validation"},{"cve":"CVE-2026-32289","cvss":6.1,"epss":0.0033,"slug":"cve-2026-32289-go-html-template-xss-in-js-template-literals","title":"Go html/template XSS in JS template literals","severity":"medium","exploited":false,"published_at":"2026-04-08T02:16:03.82+00:00","url":"https://junglewise.ai/threats/cve-2026-32289-go-html-template-xss-in-js-template-literals"},{"cve":"CVE-2026-32288","cvss":5.5,"epss":0.0018,"slug":"cve-2026-32288-go-archive-tar-unbounded-memory-allocation-in-sparse-map-parsing","title":"Go archive/tar unbounded memory allocation in sparse map parsing","severity":"medium","exploited":false,"published_at":"2026-04-08T02:16:03.707+00:00","url":"https://junglewise.ai/threats/cve-2026-32288-go-archive-tar-unbounded-memory-allocation-in-sparse-map-parsing"},{"cve":"CVE-2026-32283","cvss":7.5,"epss":0.0067,"slug":"cve-2026-32283-google-go-crypto-tls-denial-of-service-via-tls-1-3-key-update","title":"Google Go crypto/tls denial of service via TLS 1.3 key update deadlock","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.58+00:00","url":"https://junglewise.ai/threats/cve-2026-32283-google-go-crypto-tls-denial-of-service-via-tls-1-3-key-update"},{"cve":"CVE-2026-32282","cvss":6.4,"epss":0.0017,"slug":"cve-2026-32282-go-standard-library-symlink-traversal-in-root-chmod-on-linux","title":"Go standard library symlink traversal in Root.Chmod on Linux","severity":"medium","exploited":false,"published_at":"2026-04-08T02:16:03.467+00:00","url":"https://junglewise.ai/threats/cve-2026-32282-go-standard-library-symlink-traversal-in-root-chmod-on-linux"},{"cve":"CVE-2026-32281","cvss":7.5,"epss":0.0037,"slug":"cve-2026-32281-google-go-crypto-x509-denial-of-service-in-certificate-validation","title":"Google Go crypto/x509 denial of service in certificate validation","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.35+00:00","url":"https://junglewise.ai/threats/cve-2026-32281-google-go-crypto-x509-denial-of-service-in-certificate-validation"},{"cve":"CVE-2026-32280","cvss":7.5,"epss":0.007,"slug":"cve-2026-32280-google-go-denial-of-service-in-crypto-x509-certificate-chain","title":"Google Go denial of service in crypto/x509 certificate chain building","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.247+00:00","url":"https://junglewise.ai/threats/cve-2026-32280-google-go-denial-of-service-in-crypto-x509-certificate-chain"},{"cve":"CVE-2026-27137","cvss":7.5,"epss":0.0066,"slug":"cve-2026-27137-google-go-crypto-x509-improper-certificate-validation-in-email","title":"Google Go crypto/x509 improper certificate validation in email constraints","severity":"high","exploited":false,"published_at":"2026-03-06T22:16:00.85+00:00","url":"https://junglewise.ai/threats/cve-2026-27137-google-go-crypto-x509-improper-certificate-validation-in-email"},{"cve":"CVE-2026-25679","cvss":7.5,"epss":0.008,"slug":"cve-2026-25679-google-go-net-url-insufficient-validation-of-ipv6-host-literals","title":"Google Go net/url insufficient validation of IPv6 host literals","severity":"high","exploited":false,"published_at":"2026-03-06T22:16:00.72+00:00","url":"https://junglewise.ai/threats/cve-2026-25679-google-go-net-url-insufficient-validation-of-ipv6-host-literals"},{"cve":"CVE-2026-27138","epss":0.0032,"slug":"cve-2026-27138-go-2026-4600-panic-in-name-constraint-checking-for-malformed","title":"GO-2026-4600 - Panic in name constraint checking for malformed certificates in crypto/x509","severity":"info","exploited":false,"published_at":"2026-03-06T21:03:42+00:00","url":"https://junglewise.ai/threats/cve-2026-27138-go-2026-4600-panic-in-name-constraint-checking-for-malformed"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"},{"name":"github.com/hashicorp/vault (Go)","slug":"github-com-hashicorp-vault","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault"}],"technology":{"hub":true,"name":"stdlib (Go)","slug":"go-stdlib","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/go-stdlib"},"most_severe":[{"cve":"CVE-2020-0601","cvss":8.1,"epss":0.8944,"slug":"cve-2020-0601-microsoft-windows-cryptoapi-spoofing-vulnerability","title":"GO-2022-0535 - Certificate validation bypass on Windows in crypto/x509","severity":"critical","exploited":true,"published_at":"2022-08-01T22:21:17+00:00","url":"https://junglewise.ai/threats/cve-2020-0601-microsoft-windows-cryptoapi-spoofing-vulnerability"},{"cve":"CVE-2026-39821","cvss":9.6,"epss":0.0069,"slug":"cve-2026-39821-go-x-net-idna-privilege-escalation-via-punycode-decoding","title":"Go x/net idna privilege escalation via Punycode decoding","severity":"critical","exploited":false,"published_at":"2026-05-22T16:16:20.41+00:00","url":"https://junglewise.ai/threats/cve-2026-39821-go-x-net-idna-privilege-escalation-via-punycode-decoding"},{"cve":"CVE-2025-22871","cvss":9.1,"epss":0.0081,"slug":"cve-2025-22871-go-net-http-request-smuggling-via-bare-lf-in-chunked-encoding","title":"Go net/http request smuggling via bare LF in chunked encoding","severity":"critical","exploited":false,"published_at":"2025-04-08T20:15:20.183+00:00","url":"https://junglewise.ai/threats/cve-2025-22871-go-net-http-request-smuggling-via-bare-lf-in-chunked-encoding"},{"cve":"CVE-2026-33810","cvss":8.2,"epss":0.0034,"slug":"cve-2026-33810-google-go-crypto-x509-improper-dns-constraint-validation","title":"Google Go crypto/x509 improper DNS constraint validation","severity":"high","exploited":false,"published_at":"2026-04-08T02:16:03.95+00:00","url":"https://junglewise.ai/threats/cve-2026-33810-google-go-crypto-x509-improper-dns-constraint-validation"},{"cve":"CVE-2020-16845","cvss":7.5,"epss":0.0473,"slug":"cve-2020-16845-go-encoding-binary-infinite-loop-in-readuvarint-and-readvarint","title":"Go encoding/binary infinite loop in ReadUvarint and ReadVarint","severity":"high","exploited":false,"published_at":"2021-12-16T19:16:40+00:00","url":"https://junglewise.ai/threats/cve-2020-16845-go-encoding-binary-infinite-loop-in-readuvarint-and-readvarint"},{"cve":"CVE-2025-61726","cvss":7.5,"epss":0.0233,"slug":"cve-2025-61726-go-net-url-memory-exhaustion-in-query-parameter-parsing","title":"Go net/url memory exhaustion in query parameter parsing","severity":"high","exploited":false,"published_at":"2026-01-28T20:16:09.713+00:00","url":"https://junglewise.ai/threats/cve-2025-61726-go-net-url-memory-exhaustion-in-query-parameter-parsing"},{"cve":"CVE-2026-33811","cvss":7.5,"epss":0.0088,"slug":"cve-2026-33811-go-net-package-double-free-in-cgo-dns-resolver","title":"Go net package double-free in cgo DNS resolver","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:42.77+00:00","url":"https://junglewise.ai/threats/cve-2026-33811-go-net-package-double-free-in-cgo-dns-resolver"},{"cve":"CVE-2026-39820","cvss":7.5,"epss":0.0087,"slug":"cve-2026-39820-go-net-mail-denial-of-service-in-email-and-date-parsing","title":"Go net/mail denial of service in email and date parsing","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:43.187+00:00","url":"https://junglewise.ai/threats/cve-2026-39820-go-net-mail-denial-of-service-in-email-and-date-parsing"},{"cve":"CVE-2026-42499","cvss":7.5,"epss":0.008,"slug":"cve-2026-42499-google-go-net-mail-denial-of-service-in-consumephrase","title":"Google Go net/mail denial of service in consumePhrase","severity":"high","exploited":false,"published_at":"2026-05-07T20:16:44.54+00:00","url":"https://junglewise.ai/threats/cve-2026-42499-google-go-net-mail-denial-of-service-in-consumephrase"},{"cve":"CVE-2026-25679","cvss":7.5,"epss":0.008,"slug":"cve-2026-25679-google-go-net-url-insufficient-validation-of-ipv6-host-literals","title":"Google Go net/url insufficient validation of IPv6 host literals","severity":"high","exploited":false,"published_at":"2026-03-06T22:16:00.72+00:00","url":"https://junglewise.ai/threats/cve-2026-25679-google-go-net-url-insufficient-validation-of-ipv6-host-literals"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}