[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-47906":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":18,"aliases":28,"duplicate_of":9,"upstream":31,"downstream":32,"duplicates":103,"related":104,"reserved_at":9,"published_at":252,"modified_at":253,"state":254,"summary":255,"references_raw":263,"kevs":295,"epss":296,"epss_history":299,"metrics":569,"affected":577},"CVE-2025-47906","If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"NVD-CWE-OTHER","Other","NVD uses this CWE ID when the weakness does not map to any existing CWE entry.","placeholder","NVD-Reserved",[],[19],{"_key":20,"name":21,"source":22,"url":23,"maturity":24,"reliability_score":25,"verified":26,"type":9,"platforms":27,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_1826ABD3EDD0263D","Exploit Reference (go.dev)","reference","https://go.dev/issue/74466","unknown",0.2,false,[],[29,30],"GO-2025-3956","BIT-golang-2025-47906",[],[33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75,77,79,81,83,85,87,89,91,93,95,97,99,101],{"_key":34},"SUSE-SU-2025:03115-1",{"_key":36},"SUSE-SU-2026:0297-1",{"_key":38},"SUSE-SU-2025:02924-1",{"_key":40},"SUSE-SU-2025:03158-1",{"_key":42},"SUSE-SU-2025:03159-1",{"_key":44},"SUSE-SU-2025:03161-1",{"_key":46},"SUSE-SU-2025:03289-1",{"_key":48},"SUSE-SU-2026:0298-1",{"_key":50},"SUSE-SU-2025:02812-1",{"_key":52},"SUSE-SU-2025:02837-1",{"_key":54},"SUSE-SU-2025:02759-1",{"_key":56},"SUSE-SU-2025:02760-1",{"_key":58},"OPENSUSE-SU-2025:15420-1",{"_key":60},"OPENSUSE-SU-2025:15422-1",{"_key":62},"OPENSUSE-SU-2025:15423-1",{"_key":64},"OPENSUSE-SU-2025:15566-1",{"_key":66},"OPENSUSE-SU-2025:15586-1",{"_key":68},"MGASA-2025-0221",{"_key":70},"DEBIAN-CVE-2025-47906",{"_key":72},"RHSA-2025:22004",{"_key":74},"RHSA-2025:22005",{"_key":76},"RHSA-2025:23833",{"_key":78},"RHSA-2025:23834",{"_key":80},"RHSA-2025:23851",{"_key":82},"UBUNTU-CVE-2025-47906",{"_key":84},"RHSA-2025:13935",{"_key":86},"RHSA-2025:13941",{"_key":88},"RHSA-2025:21856",{"_key":90},"RHSA-2025:22181",{"_key":92},"RHSA-2025:22668",{"_key":94},"RHSA-2025:22899",{"_key":96},"RHSA-2025:23733",{"_key":98},"RHSA-2025:23737",{"_key":100},"RHSA-2025:23740",{"_key":102},"RHSA-2025:23741",[],[105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,140,142,144,146,148,150,152,154,156,158,160,162,164,166,168,170,172,174,176,178,180,182,184,186,188,190,192,194,196,198,200,202,204,206,208,210,212,214,216,218,220,222,224,226,228,230,232,234,236,238,240,242,244,246,248,250],{"_key":34},{"_key":36},{"_key":84},{"_key":86},{"_key":88},{"_key":72},{"_key":74},{"_key":90},{"_key":92},{"_key":94},{"_key":96},{"_key":98},{"_key":100},{"_key":102},{"_key":76},{"_key":78},{"_key":80},{"_key":38},{"_key":40},{"_key":42},{"_key":44},{"_key":46},{"_key":48},{"_key":50},{"_key":52},{"_key":54},{"_key":56},{"_key":58},{"_key":60},{"_key":62},{"_key":64},{"_key":66},{"_key":68},{"_key":139},"CGA-2PC3-6XJM-2RFM",{"_key":141},"CGA-2PRQ-9PVV-8X7M",{"_key":143},"CGA-38C7-2M7X-FJGP",{"_key":145},"CGA-49CV-99JM-2F4P",{"_key":147},"CGA-4PVQ-F3RJ-6V77",{"_key":149},"CGA-4X75-XV3G-5QV7",{"_key":151},"CGA-5GJM-PCGW-63QG",{"_key":153},"CGA-5R6C-2R69-X28Q",{"_key":155},"CGA-7653-J6W3-MHQG",{"_key":157},"CGA-78PR-84W2-2782",{"_key":159},"CGA-7GWM-74G7-543J",{"_key":161},"CGA-8979-7HJ5-VPMH",{"_key":163},"CGA-8F9R-JWV4-H59Q",{"_key":165},"CGA-94QW-9CQH-JCXJ",{"_key":167},"CGA-999H-WMC7-7QQ3",{"_key":169},"CGA-9C5W-8824-V2MW",{"_key":171},"CGA-9G95-J86G-4FV4",{"_key":173},"CGA-9HW2-R2Q3-V9P9",{"_key":175},"CGA-C3Q2-4H9G-V4H4",{"_key":177},"CGA-C3QW-8762-2HM2",{"_key":179},"CGA-C5XP-FQ4V-FHR3",{"_key":181},"CGA-F273-QXP7-33FH",{"_key":183},"CGA-F6XG-5HR6-QGGH",{"_key":185},"CGA-F8V5-WC49-XPX3",{"_key":187},"CGA-FH9V-9PPC-6V6V",{"_key":189},"CGA-FV5R-2F77-VMRH",{"_key":191},"CGA-G3HR-F8VM-X3JV",{"_key":193},"CGA-G83X-3PXV-FM73",{"_key":195},"CGA-GCHF-J769-W2CW",{"_key":197},"CGA-GQ75-FM9H-P6MC",{"_key":199},"CGA-GVGF-PF4R-3GR2",{"_key":201},"CGA-HCJH-FFF7-G5RC",{"_key":203},"CGA-HGC9-64FP-83C9",{"_key":205},"CGA-HJMM-MJGV-GF8W",{"_key":207},"CGA-HP97-MF3R-MW64",{"_key":209},"CGA-J39V-H775-7VQH",{"_key":211},"CGA-J7P9-RPWM-X947",{"_key":213},"CGA-JG72-W85Q-WQ5P",{"_key":215},"CGA-JJV9-755C-W48J",{"_key":217},"CGA-MF7M-6GXR-Q46X",{"_key":219},"CGA-MFMH-F38Q-CXWJ",{"_key":221},"CGA-P2CV-G5W4-XP4H",{"_key":223},"CGA-PVR9-545X-H5M7",{"_key":225},"CGA-Q9PF-CH59-VXCX",{"_key":227},"CGA-R57J-X57M-FRXW",{"_key":229},"CGA-R9J7-3J48-HW83",{"_key":231},"CGA-RC52-46R6-WX29",{"_key":233},"CGA-RRMF-WF36-V44R",{"_key":235},"CGA-W988-2X63-GCP7",{"_key":237},"CGA-W9XR-7VW4-H6FR",{"_key":239},"CGA-WF26-H6WG-X795",{"_key":241},"CGA-WHVW-MW55-FV8C",{"_key":243},"CGA-WQQ7-HRV8-QFC9",{"_key":245},"CGA-X84C-J6X4-5Q6P",{"_key":247},"CGA-XP3F-WHV5-PV64",{"_key":249},"CGA-XQXF-XX87-3W97",{"_key":251},"CGA-767V-H7FP-9HF6","2025-09-18T18:41:11.847Z","2025-11-04T21:10:54.782Z","Analyzed",{"cisa_kev":26,"cisa_ransomware":26,"cisa_vendor":9,"epss_severity":256,"epss_score":257,"severity":258,"severity_score":259,"severity_version":260,"severity_source":261,"severity_vector":262,"severity_status":254},"low",0.00044,"medium",6.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",[264,272,279,286,291],{"url":265,"sources":266,"tags":269},"https://go.dev/cl/691775",[261,267,268],"nvd","osv_go",[270,271],"Patch","FIX",{"url":23,"sources":273,"tags":274},[261,267,268],[275,276,277,278],"Exploit","Issue Tracking","Third Party Advisory","REPORT",{"url":280,"sources":281,"tags":282},"https://groups.google.com/g/golang-announce/c/x5MKroML2yM",[261,267,268],[283,284,285],"Mailing List","Release Notes","WEB",{"url":287,"sources":288,"tags":289},"https://pkg.go.dev/vuln/GO-2025-3956",[261,267],[290],"Vendor Advisory",{"url":292,"sources":293,"tags":294},"http://www.openwall.com/lists/oss-security/2025/08/06/1",[261,267],[283,276],[],{"date":297,"score":257,"percentile":298},"2026-06-04",0.14,[300,304,308,311,314,316,319,322,325,328,331,334,337,340,343,346,349,352,356,359,362,365,369,372,375,378,381,384,387,390,393,396,399,402,404,406,409,412,415,418,421,424,427,430,433,436,439,443,446,449,453,456,459,462,465,468,471,474,477,480,483,486,489,492,495,498,500,503,506,508,510,513,515,518,521,524,528,531,534,537,540,543,545,548,551,554,557,560,563,566],{"date":301,"score":302,"percentile":303},"2025-11-04",0.00024,0.05028,{"date":305,"score":306,"percentile":307},"2025-11-05",0.00025,0.0563,{"date":309,"score":306,"percentile":310},"2025-11-06",0.05749,{"date":312,"score":306,"percentile":313},"2025-11-07",0.05761,{"date":315,"score":306,"percentile":313},"2025-11-08",{"date":317,"score":306,"percentile":318},"2025-11-09",0.05754,{"date":320,"score":306,"percentile":321},"2025-11-10",0.05732,{"date":323,"score":306,"percentile":324},"2025-11-11",0.05762,{"date":326,"score":306,"percentile":327},"2025-11-12",0.05807,{"date":329,"score":306,"percentile":330},"2025-11-13",0.0584,{"date":332,"score":306,"percentile":333},"2025-11-14",0.05874,{"date":335,"score":306,"percentile":336},"2025-11-15",0.05901,{"date":338,"score":306,"percentile":339},"2025-11-16",0.05917,{"date":341,"score":306,"percentile":342},"2025-11-17",0.05902,{"date":344,"score":306,"percentile":345},"2025-11-18",0.03498,{"date":347,"score":306,"percentile":348},"2025-11-19",0.03549,{"date":350,"score":306,"percentile":351},"2025-11-20",0.03617,{"date":353,"score":354,"percentile":355},"2025-11-21",0.00019,0.03941,{"date":357,"score":354,"percentile":358},"2025-11-22",0.03945,{"date":360,"score":354,"percentile":361},"2025-11-23",0.03936,{"date":363,"score":354,"percentile":364},"2025-11-24",0.03919,{"date":366,"score":367,"percentile":368},"2025-11-25",0.0002,0.04216,{"date":370,"score":367,"percentile":371},"2025-11-26",0.0426,{"date":373,"score":367,"percentile":374},"2025-11-27",0.04282,{"date":376,"score":367,"percentile":377},"2025-11-28",0.04265,{"date":379,"score":367,"percentile":380},"2025-11-29",0.0432,{"date":382,"score":367,"percentile":383},"2025-11-30",0.04321,{"date":385,"score":367,"percentile":386},"2025-12-01",0.04411,{"date":388,"score":367,"percentile":389},"2025-12-02",0.04426,{"date":391,"score":367,"percentile":392},"2025-12-03",0.04445,{"date":394,"score":367,"percentile":395},"2025-12-04",0.04392,{"date":397,"score":367,"percentile":398},"2025-12-05",0.0446,{"date":400,"score":367,"percentile":401},"2025-12-06",0.04472,{"date":403,"score":367,"percentile":401},"2025-12-07",{"date":405,"score":367,"percentile":401},"2025-12-08",{"date":407,"score":367,"percentile":408},"2025-12-09",0.04522,{"date":410,"score":367,"percentile":411},"2025-12-10",0.04561,{"date":413,"score":367,"percentile":414},"2025-12-11",0.04563,{"date":416,"score":367,"percentile":417},"2025-12-12",0.04579,{"date":419,"score":367,"percentile":420},"2025-12-13",0.04619,{"date":422,"score":367,"percentile":423},"2025-12-14",0.04605,{"date":425,"score":367,"percentile":426},"2025-12-15",0.04565,{"date":428,"score":367,"percentile":429},"2025-12-16",0.04576,{"date":431,"score":367,"percentile":432},"2025-12-17",0.04631,{"date":434,"score":367,"percentile":435},"2025-12-18",0.04664,{"date":437,"score":367,"percentile":438},"2025-12-19",0.0465,{"date":440,"score":441,"percentile":442},"2025-12-20",0.00012,0.01311,{"date":444,"score":441,"percentile":445},"2025-12-21",0.01322,{"date":447,"score":441,"percentile":448},"2025-12-22",0.01324,{"date":450,"score":451,"percentile":452},"2025-12-23",0.00015,0.02267,{"date":454,"score":451,"percentile":455},"2025-12-24",0.02281,{"date":457,"score":451,"percentile":458},"2025-12-25",0.02288,{"date":460,"score":451,"percentile":461},"2025-12-26",0.0229,{"date":463,"score":451,"percentile":464},"2025-12-27",0.02274,{"date":466,"score":451,"percentile":467},"2025-12-28",0.02289,{"date":469,"score":451,"percentile":470},"2025-12-29",0.02279,{"date":472,"score":451,"percentile":473},"2025-12-30",0.02272,{"date":475,"score":451,"percentile":476},"2025-12-31",0.02261,{"date":478,"score":451,"percentile":479},"2026-01-01",0.02317,{"date":481,"score":451,"percentile":482},"2026-01-02",0.02318,{"date":484,"score":451,"percentile":485},"2026-01-03",0.02321,{"date":487,"score":451,"percentile":488},"2026-01-04",0.02254,{"date":490,"score":451,"percentile":491},"2026-01-05",0.02257,{"date":493,"score":451,"percentile":494},"2026-01-06",0.02244,{"date":496,"score":451,"percentile":497},"2026-01-07",0.02259,{"date":499,"score":451,"percentile":455},"2026-01-08",{"date":501,"score":451,"percentile":502},"2026-01-09",0.02295,{"date":504,"score":451,"percentile":505},"2026-01-10",0.02304,{"date":507,"score":451,"percentile":458},"2026-01-11",{"date":509,"score":451,"percentile":452},"2026-01-12",{"date":511,"score":451,"percentile":512},"2026-01-13",0.02255,{"date":514,"score":451,"percentile":497},"2026-01-14",{"date":516,"score":451,"percentile":517},"2026-01-15",0.02252,{"date":519,"score":451,"percentile":520},"2026-01-16",0.02251,{"date":522,"score":451,"percentile":523},"2026-01-17",0.02256,{"date":525,"score":526,"percentile":527},"2026-01-18",0.00018,0.03905,{"date":529,"score":526,"percentile":530},"2026-01-19",0.0386,{"date":532,"score":526,"percentile":533},"2026-01-20",0.0383,{"date":535,"score":526,"percentile":536},"2026-01-21",0.0382,{"date":538,"score":451,"percentile":539},"2026-01-22",0.02335,{"date":541,"score":451,"percentile":542},"2026-01-23",0.02345,{"date":544,"score":526,"percentile":527},"2026-01-24",{"date":546,"score":354,"percentile":547},"2026-01-25",0.04194,{"date":549,"score":354,"percentile":550},"2026-01-26",0.04183,{"date":552,"score":354,"percentile":553},"2026-01-27",0.04171,{"date":555,"score":354,"percentile":556},"2026-01-28",0.04154,{"date":558,"score":367,"percentile":559},"2026-01-29",0.04289,{"date":561,"score":367,"percentile":562},"2026-01-30",0.04292,{"date":564,"score":367,"percentile":565},"2026-01-31",0.04269,{"date":567,"score":367,"percentile":568},"2026-02-01",0.04368,[570,575],{"source":261,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":571,"cvss_v4_0":9},{"baseScore":259,"baseSeverity":572,"vectorString":262,"impactScore":573,"exploitabilityScore":574},"MEDIUM",4.2,10,{"source":267,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":576,"cvss_v4_0":9},{"baseScore":259,"baseSeverity":572,"vectorString":262,"impactScore":573,"exploitabilityScore":574},[578,593,602],{"ecosystem":9,"name":579,"vendor":580,"product":579,"cpe_part":581,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":582},"os/exec","go standard library","a",[583,588],{"version":584,"is_range":585,"range_type":261,"version_start":9,"version_start_type":9,"version_end":586,"version_end_type":587,"fixed_in":9},"\u003C 1.23.12",true,"1.23.12","excluding",{"version":589,"is_range":585,"range_type":261,"version_start":590,"version_start_type":591,"version_end":592,"version_end_type":587,"fixed_in":9},">= 1.24.0, \u003C 1.24.6","1.24.0","including","1.24.6",{"ecosystem":9,"name":594,"vendor":595,"product":594,"cpe_part":581,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":596},"go","golang",[597,600],{"version":598,"is_range":585,"range_type":599,"version_start":9,"version_start_type":9,"version_end":586,"version_end_type":587,"fixed_in":9},"lt1.23.12","cpe",{"version":601,"is_range":585,"range_type":599,"version_start":590,"version_start_type":591,"version_end":592,"version_end_type":587,"fixed_in":9},"gte1.24.0_lt1.24.6",{"ecosystem":603,"name":604,"vendor":603,"product":604,"cpe_part":9,"purl_type":595,"purl_namespace":9,"purl_name":604,"source":9,"versions":605},"Go","stdlib",[606],{"version":607,"is_range":585,"range_type":608,"version_start":590,"version_start_type":591,"version_end":592,"version_end_type":587,"fixed_in":9},"gte1_24_0_lt1_24_6","semver"]