Vulnerabilities
Vulnerable Software
Golang:  >> Go  >> 1.26.2  Security Vulnerabilities
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
CVSS Score
5.9
EPSS Score
0.002
Published
2026-05-07
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVSS Score
7.5
EPSS Score
0.008
Published
2026-05-07
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
CVSS Score
7.5
EPSS Score
0.008
Published
2026-05-07


Contact Us

Shodan ® - All rights reserved