Known vulnerabilities in go-toolset

Vendor: OpenAnolis
Software: go-toolset
Software CPE: cpe:2.3:o:openanolis:go-toolset:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 76
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting go-toolset go-toolset is affected by 76 known vulnerabilities: 8 high, 53 medium, 15 low Critical High Medium Low

Vulnerabilities (76)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
CWE-367 Low
No
No
1.25.9-1.0.1 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 49 more
#VU140604 - Memory corruption
CVE-2026-27144
CWE-119 Low
No
No
1.25.9-1.0.1 31.07.2026 SB2026073125
SB2026073157
SB2026073158
and 11 more
#VU140603 - Integer overflow
CVE-2026-27143
CWE-190 Low
No
No
1.25.9-1.0.1 31.07.2026 SB2026073125
SB2026073157
SB2026073158
and 11 more
#VU140601 - Protection Mechanism Failure
CVE-2026-27140
CWE-693 High
No
No
1.25.9-1.0.1 31.07.2026 SB2026073125
SB2026073155
SB2026073156
and 15 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
1.25.9-1.0.1 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 65 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
1.25.9-1.0.1 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 59 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
1.24.6-1, 1.25.8-1.0.1 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 130 more
#VU124035 - Protection Mechanism Failure
CVE-2025-61731
CWE-693 High
No
No
1.24.6-1, 1.25.8-1.0.1 16.03.2026 SB2026031680
SB20260316116
SB2026032049
and 18 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
1.25.7-1.0.1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 142 more
#VU124033 - Improper input validation
CVE-2025-61728
CWE-20 Medium
No
No
1.25.7-1.0.1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 45 more
#VU123445 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-61732
CWE-94 Medium
No
No
1.25.7-1.0.1 03.03.2026 SB2026030334
SB2026030343
SB2026030375
and 25 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
1.25.7-1.0.1 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 112 more
#VU119235 - Resource exhaustion
CVE-2025-61729
CWE-400 Medium
No
No
1.24.6-1, 1.25.5-1.0.1 06.12.2025 SB2025120604
SB20251210172
SB20251210173
and 146 more
#VU118190 - Resource exhaustion
CVE-2025-58183
CWE-400 Medium
No
No
1.24.6-1, 1.25.3-2.0.2 07.11.2025 SB2025110705
SB2025110725
SB2025110726
and 177 more
#VU114341 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-4674
CWE-78 High
No
No
1.24.6-1 21.08.2025 SB2025082138
SB2025082164
SB2025082165
and 19 more
#VU114079 - Improper input validation
CVE-2025-47906
CWE-20 Low
No
No
1.24.6-1, 1.25.3-2.0.2 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 130 more
#VU110251 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4673
CWE-200 Low
No
No
1.24.4-1 07.06.2025 SB2025060701
SB2025060702
SB2025061002
and 35 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
1.24.4-1 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU103457 - Improper input validation
CVE-2024-45341
CWE-20 Low
No
No
1.24.4-1 30.01.2025 SB2025013039
SB2025013043
SB2025013044
and 23 more
#VU103455 - Exposure of sensitive information to an unauthorized actor
CVE-2024-45336
CWE-200 Low
No
No
1.24.4-1 30.01.2025 SB2025013039
SB2025013043
SB2025013044
and 38 more


Showing elements 1 - 20 out of 76