#Go
All CosmicBytez Labs articles tagged #Go, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-74799: SiYuan pprof Debug Endpoints Exposed Without Authentication
SiYuan before 3.7.4 exposes Go pprof debug endpoints unauthenticated, leaking in-memory secrets including API keys and auth codes.
- Security
CVE-2026-72811: SiYuan SQL Injection in Backlink Search Scores Perfect 10.0
SiYuan note-taking app up to v3.7.2 is vulnerable to SQL injection via stored block metadata in the backlink search query path.
- Security
CVE-2026-15704: Critical Auth Bypass in Eclipse BaSyx Go Components
Eclipse BaSyx Go Components up to v1.0.0 contains a CVSS 9.8 authorization bypass caused by inconsistent trailing-slash handling between the ABAC...
- News
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
A new supply chain attack campaign dubbed BufferZoneCorp has been observed using sleeper packages in RubyGems and Go module registries to push...
- Security
CVE-2026-35392: Critical Path Traversal in goshs Go HTTP
A critical CVSS 9.8 path traversal vulnerability in goshs, a SimpleHTTPServer written in Go, allows unauthenticated attackers to write arbitrary files via...