rpm package
almalinux/delve
pkg:rpm/almalinux/delve
Vulnerabilities (94)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56862 | Hig | 7.5 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef | |
| CVE-2026-56860 | Med | 5.9 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b | |
| CVE-2026-56859 | Hig | 7.5 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | |
| CVE-2026-56858 | Med | 6.1 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | |
| CVE-2026-56853 | Hig | 7.5 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. | |
| CVE-2026-33818 | Hig | 7.5 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Aug 13, 2026 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. | |
| CVE-2026-39822 | Hig | 7.8 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb | |
| CVE-2026-27145 | Med | 6.5 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | Jun 2, 2026 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratic | |
| CVE-2026-39821 | Cri | 9.6 | < 1.26.1-1.module_el8.10.0+4223+bd807c2e | 1.26.1-1.module_el8.10.0+4223+bd807c2e | May 22, 2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program | |
| CVE-2026-42501 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can ser | |
| CVE-2026-42499 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | |
| CVE-2026-39836 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). | |
| CVE-2026-39826 | Med | 6.1 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | If a trusted template author were to write a tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the block. | |
| CVE-2026-39825 | Med | 5.3 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.Pa | |
| CVE-2026-39823 | Med | 6.1 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a tag's attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the attribute, the escaper would fail to similarly escape it, le | |
| CVE-2026-39820 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. | |
| CVE-2026-39819 | Med | 5.3 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink. | |
| CVE-2026-39817 | Med | 5.9 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem. | |
| CVE-2026-33814 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. | |
| CVE-2026-33811 | Hig | 7.5 | < 1.25.2-1.module_el8.10.0+4074+24330916 | 1.25.2-1.module_el8.10.0+4074+24330916 | May 7, 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. |
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratic
- affected < 1.26.1-1.module_el8.10.0+4223+bd807c2efixed 1.26.1-1.module_el8.10.0+4223+bd807c2e
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can ser
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
If a trusted template author were to write a tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the block.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.Pa
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a tag's attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the attribute, the escaper would fail to similarly escape it, le
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
- affected < 1.25.2-1.module_el8.10.0+4074+24330916fixed 1.25.2-1.module_el8.10.0+4074+24330916
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
Page 1 of 5