go 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk input validation and vendor risk denial of service などに関し、一部は vendor impact unexpected behavior を招き、vendor surface production workloads and vendor surface software deployment 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-58190 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | [email protected] | 5.3 | 0.02% | 2026-02-05 | 2026-02-18 |
| CVE-2025-47911 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | [email protected] | 5.3 | 0.02% | 2026-02-05 | 2026-02-18 |
| CVE-2025-68120 | To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode. | [email protected] | 5.4 | 0.03% | 2025-12-30 | 2026-01-06 |
| CVE-2025-47913 | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. | [email protected] | 7.5 | 0.02% | 2025-11-13 | 2026-01-09 |
| CVE-2025-22869 | SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted. | [email protected] | 7.5 | 0.61% | 2025-02-26 | 2025-05-01 |
| CVE-2025-22868 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. | [email protected] | 7.5 | 0.12% | 2025-02-26 | 2025-05-01 |