stdlib
Go157 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting stdlibpage 4 of 4
- CVE-2026-33814HIGHCVSS 7.5EG 7.5✓ Fixed in 1.26.32026-05-07
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
- CVE-2026-39820HIGHCVSS 7.5EG 7.5✓ Fixed in 1.26.32026-05-07
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
- CVE-2026-39823MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.26.32026-05-07
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the esca…
- CVE-2026-39825MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.26.32026-05-07
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query …
- CVE-2026-39826MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.26.32026-05-07
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.
- CVE-2026-39836HIGHCVSS 7.5EG 7.5✓ Fixed in 1.26.32026-05-07
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
- CVE-2026-42499HIGHCVSS 7.5EG 7.5✓ Fixed in 1.26.32026-05-07
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Check whether stdlib is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for stdlib CVEs against the assets you own.
Start Free Scan →