{"grype_matches":[{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-07","epss":0.00692,"percentile":0.5135}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-07","epss":0.00692,"percentile":0.5135}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"5487db2744f6a759","cpes":["cpe:2.3:a:google:grpc:v1.82.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.82.1","type":"go-module","version":"v1.82.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.82.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2v4p-qf9q-27wj","versionConstraint":"<1.82.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.82.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-2v4p-qf9q-27wj","fix":{"state":"fixed","versions":["1.82.2"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"1.82.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84445","cwe":"CWE-129","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84445","cwe":"CWE-248","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84445","date":"2026-10-07","epss":0.00641,"percentile":0.49094}],"risk":0.51921,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj","https://github.com/grpc/grpc-go/issues/9354","https://github.com/grpc/grpc-go/pull/9365","https://github.com/grpc/grpc-go/pull/9366","https://github.com/grpc/grpc-go/pull/9367","https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7","https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4","https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f","https://github.com/grpc/grpc-go/releases/tag/v1.82.2","https://github.com/grpc/grpc-go/releases/tag/v1.83.2","https://nvd.nist.gov/vuln/detail/CVE-2026-84445"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2v4p-qf9q-27wj","description":"gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers"},"relatedVulnerabilities":[{"id":"CVE-2026-84445","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84445","cwe":"CWE-129","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84445","cwe":"CWE-248","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84445","date":"2026-10-07","epss":0.00641,"percentile":0.49094}],"urls":["https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7","https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4","https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f","https://github.com/grpc/grpc-go/issues/9354","https://github.com/grpc/grpc-go/pull/9365","https://github.com/grpc/grpc-go/pull/9366","https://github.com/grpc/grpc-go/pull/9367","https://github.com/grpc/grpc-go/releases/tag/v1.82.2","https://github.com/grpc/grpc-go/releases/tag/v1.83.2","https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84445","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2."}]},{"artifact":{"id":"5487db2744f6a759","cpes":["cpe:2.3:a:google:grpc:v1.82.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.82.1","type":"go-module","version":"v1.82.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.83.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vp52-pcj8-j9qc","versionConstraint":"<=1.83.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.82.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vp52-pcj8-j9qc","fix":{"state":"fixed","versions":["1.83.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.83.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84304","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84304","date":"2026-10-07","epss":0.00609,"percentile":0.47481}],"risk":0.49328999999999995,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc","https://nvd.nist.gov/vuln/detail/CVE-2026-84304","https://github.com/grpc/grpc-go/pull/9331","https://github.com/grpc/grpc-go/pull/9333","https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176","https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77","https://github.com/grpc/grpc-go/releases/tag/v1.83.1"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vp52-pcj8-j9qc","description":"gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation"},"relatedVulnerabilities":[{"id":"CVE-2026-84304","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84304","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84304","date":"2026-10-07","epss":0.00609,"percentile":0.47481}],"urls":["https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176","https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77","https://github.com/grpc/grpc-go/pull/9331","https://github.com/grpc/grpc-go/pull/9333","https://github.com/grpc/grpc-go/releases/tag/v1.83.1","https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84304","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1."}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-07","epss":0.0055,"percentile":0.44257}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-07","epss":0.0055,"percentile":0.44257}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"5487db2744f6a759","cpes":["cpe:2.3:a:google:grpc:v1.82.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.82.1","type":"go-module","version":"v1.82.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.83.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qc2q-p7wx-3px3","versionConstraint":"<=1.83.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.82.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qc2q-p7wx-3px3","fix":{"state":"fixed","versions":["1.83.1"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"1.83.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84303","cwe":"CWE-178","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84303","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84303","date":"2026-10-07","epss":0.00311,"percentile":0.21951}],"risk":0.17571499999999998,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3","https://nvd.nist.gov/vuln/detail/CVE-2026-84303","https://github.com/grpc/grpc-go/pull/9332","https://github.com/grpc/grpc-go/pull/9335","https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8","https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe","https://github.com/grpc/grpc-go/releases/tag/v1.83.1"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qc2q-p7wx-3px3","description":"gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion"},"relatedVulnerabilities":[{"id":"CVE-2026-84303","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84303","cwe":"CWE-178","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84303","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84303","date":"2026-10-07","epss":0.00311,"percentile":0.21951}],"urls":["https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8","https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe","https://github.com/grpc/grpc-go/pull/9332","https://github.com/grpc/grpc-go/pull/9335","https://github.com/grpc/grpc-go/releases/tag/v1.83.1","https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84303","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1."}]},{"artifact":{"id":"72d3c739100187e3","cpes":["cpe:2.3:a:opentelemetry:opentelemetry:v1.43.0:*:*:*:*:go:*:*"],"name":"go.opentelemetry.io/otel","purl":"pkg:golang/go.opentelemetry.io/otel@v1.43.0","type":"go-module","version":"v1.43.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:mYIM03dnh5zfN7HautFE4ieIig9amkNANT+xcVxAj9I=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5158","versionConstraint":">=1.41.0,<1.42.0||>=1.43.0,<1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel","version":"v1.43.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5158","fix":{"state":"fixed","versions":["1.42.0","1.44.0"],"available":[{"date":"2026-03-06","kind":"release","version":"1.42.0"},{"date":"2026-05-27","kind":"release","version":"1.44.0"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-07","epss":0.00336,"percentile":0.24879}],"risk":0.17304000000000003,"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/7880"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835","description":"Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel"},"relatedVulnerabilities":[{"id":"CVE-2026-41178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-07","epss":0.00336,"percentile":0.24879}],"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/7880","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41178","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue."},{"id":"GHSA-5wrp-cwcj-q835","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41178","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41178","date":"2026-10-07","epss":0.00336,"percentile":0.24879}],"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835","https://nvd.nist.gov/vuln/detail/CVE-2026-41178","https://github.com/open-telemetry/opentelemetry-go/pull/7880"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-5wrp-cwcj-q835","description":"opentelemetry-go's baggage parsing no longer caps raw header length"}]},{"artifact":{"id":"db9a929d5b4da6de","cpes":["cpe:2.3:a:golang:go:1.25.12:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.12","type":"go-module","version":"go1.25.12","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.12"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-07","epss":0.0031,"percentile":0.21792}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-07","epss":0.0031,"percentile":0.21792}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"bd844e5ecf81c4aa","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace:v1.33.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.33.0","type":"go-module","version":"v1.33.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Vh5HayB/0HHfOQA7Ctx69E/Y/DcQSMPpKANYVMQ7fBA=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","version":"v1.33.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"de2cf6cba444db64","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracegrpc:v1.33.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.33.0","type":"go-module","version":"v1.33.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5pojmb1U1AogINhN3SurB+zm/nIcusopeBNp42f45QM=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","version":"v1.33.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"751b6a0f1421411e","cpes":["cpe:2.3:a:otel:sdk:v1.43.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.43.0","type":"go-module","version":"v1.43.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:pi5mE86i5rTeLXqoF/hhiBtUNcrAGHLKQdhg4h4V9Dg=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.43.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"291a80453abbabd7","cpes":["cpe:2.3:a:google:cel-go:v0.23.2:*:*:*:*:*:*:*","cpe:2.3:a:google:cel_go:v0.23.2:*:*:*:*:*:*:*"],"name":"github.com/google/cel-go","purl":"pkg:golang/github.com/google/cel-go@v0.23.2","type":"go-module","version":"v0.23.2","language":"go","licenses":[],"metadata":{"h1Digest":"h1:UdEe3CvQh3Nv+E/j9r1Y//WO0K0cSyD7/y0bzyLIMI4=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.29.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gcjh-h69q-9w9g","versionConstraint":">=0.22.0,<=0.28.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/google/cel-go","version":"v0.23.2"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-gcjh-h69q-9w9g","fix":{"state":"fixed","versions":["0.29.0"],"available":[{"date":"2026-07-25","kind":"first-observed","version":"0.29.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/cel-expr/cel-go/security/advisories/GHSA-gcjh-h69q-9w9g"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gcjh-h69q-9w9g","description":"cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag"},"relatedVulnerabilities":[]},{"artifact":{"id":"ca3988a307528103","cpes":["cpe:2.3:a:golang:text:v0.40.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.40.0","type":"go-module","version":"v0.40.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=","mainModule":"github.com/kong/kubernetes-ingress-controller/v3","architecture":"amd64","goCompiledVersion":"go1.25.12"},"locations":[{"path":"/manager","layerID":"sha256:255ce767d23df0ac7760d7f61dc0c2e28b194639a7ffa5f7ff4198235fe28a1b","accessPath":"/manager","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.41.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6629","versionConstraint":"<0.41.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.40.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6629","fix":{"state":"fixed","versions":["0.41.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.41.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/80112"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/793360","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-56851","cvss":[],"urls":["https://go.dev/cl/793360","https://go.dev/issue/80112","https://pkg.go.dev/vuln/GO-2026-6629"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56851","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."}]}],"grade":"F","score":"37.00","as_of":"2026-10-08T17:33:49.728Z","grype_db_version":"2026-10-08T06:33:47.000Z"}