Search CVE reports


Toggle filters

41 – 43 of 43 results


CVE-2022-41724

Medium priority

Some fixes available 6 of 13

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all...

13 affected packages

golang-1.19, golang-1.20, golang, golang-1.6, golang-1.8...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-1.19 Not in release Not in release Not in release Not in release
golang-1.20 Not in release Not affected Not affected Not in release
golang Not in release Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Not affected
golang-1.9 Not in release Not in release Not in release Not affected
golang-1.10 Not in release Not in release Not in release Not affected
golang-1.13 Not in release Vulnerable Vulnerable Vulnerable
golang-1.14 Not in release Not in release Vulnerable Not in release
golang-1.16 Not in release Not in release Vulnerable Vulnerable
golang-1.17 Not in release Fixed Not in release Not in release
golang-1.18 Not in release Fixed Fixed Fixed
golang-1.21 Not affected Not affected Not affected Not in release
Show all 13 packages Show less packages

CVE-2022-41723

Medium priority

Some fixes available 11 of 30

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

16 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang, golang-1.6...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Vulnerable Not in release Not in release
google-guest-agent Fixed Fixed Fixed Vulnerable
containerd Not affected Not affected Not affected Not affected
golang Not in release Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Vulnerable
golang-1.9 Not in release Not in release Not in release Vulnerable
golang-1.10 Not in release Not in release Not in release Vulnerable
golang-1.13 Not in release Vulnerable Vulnerable Vulnerable
golang-1.14 Not in release Not in release Vulnerable Not in release
golang-1.16 Not in release Not in release Vulnerable Vulnerable
golang-1.17 Not in release Fixed Not in release Not in release
golang-1.18 Not in release Fixed Fixed Fixed
golang-1.19 Not in release Not in release Not in release Not in release
golang-1.20 Not in release Not affected Not affected Not in release
golang-1.21 Not affected Not affected Not affected Not in release
Show all 16 packages Show less packages

CVE-2022-30636

Low priority
Not affected

httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a different path separator (\ vs....

14 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Not affected
golang-1.9 Not in release Not in release Not in release Not affected
golang-1.10 Not in release Not in release Not in release Not affected
golang-1.13 Not in release Not affected Not affected Not affected
golang-1.14 Not in release Not in release Not affected
golang-1.16 Not in release Not in release Not affected Not affected
golang-1.17 Not in release Not affected Not in release
golang-1.18 Not in release Not affected Not affected Not affected
golang-1.19 Not in release Not in release Not in release
golang-1.20 Not in release Not affected Not affected
golang-1.21 Not affected Not affected Not affected
golang-1.22 Not affected Not affected Not affected
Show all 14 packages Show less packages