[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-MGASA-2026-0341":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":34,"duplicates":35,"related":36,"reserved_at":9,"published_at":37,"modified_at":38,"state":9,"summary":39,"references_raw":41,"kevs":58,"epss":9,"epss_history":59,"metrics":60,"affected":61},"MGASA-2026-0341","Updated golang packages fix security vulnerabilities\n\nCVE-2026-56865  A malicious GOPROXY was previously capable of forging up\nto two sumdb tiles that allow for a requested module to bypass the\nGOSUMDB check and persist attacker-controlled module content to a local\nGo module cache.\nCVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary\nmodule content not contained within the transparency log.\nCVE-2026-56859 Previously, DecodeElement would reset the depth counter\ncausing it to never fire; this could lead to stack exhaustion.\nCVE-2026-56853 When a server is configured to support unencrypted\nHTTP/2, it reads a few bytes from each new connection to see if they\ncontain the HTTP/2 client preface. Previously, this was being done with\nno timeout applied. ReadHeaderTimeout is now applied for this.\nCVE-2026-56860 Previously, resolving relative paths containing parent\ndirectory (|..|) segments performed string conversions and buffer\nrewrites on each step, resulting in quadratic time complexity and high\nmemory allocation overhead.\nCVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the\nsize of a parameter value overflows the message buffer.\nCVE-2026-56862 Previously, we always counted handshake messages, such as\nKeyUpdate, as state-advancing, regardless of whether a handshake has\nbeen completed or not. As a result, a malicious client can keep sending\nKeyUpdate messages to force the server to keep performing key derivation\noperations indefinitely.\nCVE-2026-56858 Previously, pathological inputs could close an unescaped\n|/| early, allowing for attack-controlled data to inject arbitrary\ncontent, potentially leading to XSS.\nCVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted\nPunycode-encoded labels that decode to an ASCII-only label. For example,\nToUnicode(\"xn--example-.com\") incorrectly returned the name\n\"example.com\" rather than an error.\nCVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack\nexhaustion when parsing deeply-nested, recursive structures.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32],{"_key":15},"CVE-2026-33818",{"_key":17},"CVE-2026-39821",{"_key":19},"CVE-2026-46600",{"_key":21},"CVE-2026-56853",{"_key":23},"CVE-2026-56858",{"_key":25},"CVE-2026-56859",{"_key":27},"CVE-2026-56860",{"_key":29},"CVE-2026-56862",{"_key":31},"CVE-2026-56864",{"_key":33},"CVE-2026-56865",[],[],[],"2026-08-30T04:17:09Z","2026-08-30T04:41:21.002923652Z",{"cisa_kev":40,"cisa_ransomware":40,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[42,48,53],{"url":43,"sources":44,"tags":46},"https://advisories.mageia.org/MGASA-2026-0341.html",[45],"osv_mageia",[47],"Advisory",{"url":49,"sources":50,"tags":51},"https://bugs.mageia.org/show_bug.cgi?id=36142",[45],[52],"REPORT",{"url":54,"sources":55,"tags":56},"https://www.openwall.com/lists/oss-security/2026/08/13/13",[45],[57],"WEB",[],[],[],[62,74],{"ecosystem":63,"name":64,"vendor":65,"product":64,"cpe_part":9,"purl_type":66,"purl_namespace":65,"purl_name":64,"source":9,"versions":67},"Mageia","golang","mageia","rpm",[68],{"version":69,"is_range":70,"range_type":71,"version_start":9,"version_start_type":9,"version_end":72,"version_end_type":73,"fixed_in":9},"lt1_25_13_1_mga10",true,"ecosystem","1.25.13-1.mga10","excluding",{"ecosystem":63,"name":64,"vendor":65,"product":64,"cpe_part":9,"purl_type":66,"purl_namespace":65,"purl_name":64,"source":9,"versions":75},[76],{"version":77,"is_range":70,"range_type":71,"version_start":9,"version_start_type":9,"version_end":78,"version_end_type":73,"fixed_in":9},"lt1_25_13_1_mga9","1.25.13-1.mga9"]