Critical
CVE-2025-68121
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th…
High
CVE-2025-61732
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Low
CVE-2025-22873
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp…
High
CVE-2025-68119
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria…
High
CVE-2025-61731
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of…
High
CVE-2025-61726
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p…