Known vulnerabilities in go1.26-openssl
Vendor:
SUSE
Software:
go1.26-openssl
Software CPE:
cpe:2.3:o:suse:go1_26-openssl:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
20
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (20)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140622 - Improper Link Resolution Before File Access ('Link Following') CVE-2026-39822 |
CWE-59 | Low | 1.26.5-150000.1.12.1, 1.26.5-150600.13.9.1 | 31.07.2026 |
SB2026073128 SB20260731126 SB20260731127 and 8 more |
||
| #VU140621 - Exposure of sensitive information to an unauthorized actor CVE-2026-42505 |
CWE-200 | Medium | 1.26.5-150000.1.12.1, 1.26.5-150600.13.9.1 | 31.07.2026 |
SB2026073128 SB20260731146 SB20260731147 and 5 more |
||
| #VU140620 - Resource exhaustion CVE-2026-27145 |
CWE-400 | Medium | 1.26.5-150000.1.12.1, 1.26.5-150600.13.9.1 | 31.07.2026 |
SB2026073127 SB2026073129 SB2026073130 and 39 more |
||
| #VU140619 - Resource exhaustion CVE-2026-42504 |
CWE-400 | Medium | 1.26.5-150000.1.12.1, 1.26.5-150600.13.9.1 | 31.07.2026 |
SB2026073127 SB20260731138 SB20260731143 and 7 more |
||
| #VU140618 - Improper Output Neutralization for Logs CVE-2026-42507 |
CWE-117 | Medium | 1.26.5-150000.1.12.1, 1.26.5-150600.13.9.1 | 31.07.2026 |
SB2026073127 SB20260731115 SB20260731143 and 6 more |
||
| #VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2026-32282 |
CWE-367 | Low | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 50 more |
||
| #VU140606 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-32289 |
CWE-79 | Medium | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB20260731139 SB20260731140 and 4 more |
||
| #VU140605 - Improper Certificate Validation CVE-2026-33810 |
CWE-295 | Medium | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073183 SB2026073184 and 7 more |
||
| #VU140604 - Memory corruption CVE-2026-27144 |
CWE-119 | Low | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073157 SB2026073158 and 11 more |
||
| #VU140603 - Integer overflow CVE-2026-27143 |
CWE-190 | Low | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073157 SB2026073158 and 11 more |
||
| #VU140602 - Allocation of Resources Without Limits or Throttling CVE-2026-32288 |
CWE-770 | Medium | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073155 SB2026073156 and 9 more |
||
| #VU140601 - Protection Mechanism Failure CVE-2026-27140 |
CWE-693 | High | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073155 SB2026073156 and 15 more |
||
| #VU140600 - Improper input validation CVE-2026-32281 |
CWE-20 | Medium | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073183 SB2026073184 and 35 more |
||
| #VU140599 - Resource exhaustion CVE-2026-32280 |
CWE-400 | Medium | 1.26.2-150000.1.6.1 | 31.07.2026 |
SB2026073125 SB2026073160 SB2026073161 and 70 more |
||
| #VU136680 - Dependency on Vulnerable Third-Party Component CVE-2026-32283 |
CWE-1395 | Medium | 1.26.2-150000.1.6.1 | 02.07.2026 |
SB2026070218 SB2026070239 SB2026070240 and 61 more |
||
| #VU124115 - Improper Authorization CVE-2026-27137 |
CWE-285 | Medium | 1.26.1-150000.1.3.1, 1.26.1-150600.13.3.1 | 19.03.2026 |
SB2026031903 SB2026031905 SB2026032422 and 9 more |
||
| #VU124116 - Error Handling CVE-2026-27138 |
CWE-388 | Medium | 1.26.1-150000.1.3.1, 1.26.1-150600.13.3.1 | 19.03.2026 |
SB2026031903 SB2026031905 SB2026032422 and 2 more |
||
| #VU124117 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-27142 |
CWE-79 | Medium | 1.26.1-150000.1.3.1, 1.26.1-150600.13.3.1 | 19.03.2026 |
SB2026031903 SB2026031904 SB2026031905 and 16 more |
||
| #VU124118 - Improper input validation CVE-2026-25679 |
CWE-20 | Medium | 1.26.1-150000.1.3.1, 1.26.1-150600.13.3.1 | 19.03.2026 |
SB2026031903 SB2026031904 SB2026031905 and 134 more |
||
| #VU124119 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-27139 |
CWE-22 | Low | 1.26.1-150000.1.3.1, 1.26.1-150600.13.3.1 | 19.03.2026 |
SB2026031903 SB2026031904 SB2026031905 and 14 more |