sonobuoy (gobinary)
Total: 8 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 8, CRITICAL: 0)
┌─────────┬────────────────┬──────────┬────────┬───────────────────┬──────────────────────────────┬──────────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────┼────────────────┼──────────┼────────┼───────────────────┼──────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ stdlib │ CVE-2026-33818 │ HIGH │ fixed │ v1.26.5 │ 1.25.13, 1.26.6, 1.27.0-rc.3 │ encoding/asn1: golang: Go encoding/asn1: Denial of Service │
│ │ │ │ │ │ │ via excessive recursion in Unmarshal... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-33818 │
│ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-39821 │ │ │ │ │ golang.org/x/net/idna: golang: net/http: │
│ │ │ │ │ │ │ golang.org/x/net/idna: Privilege escalation via incorrect │
│ │ │ │ │ │ │ Punycode label processing │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-39821 │
│ ├────────────────┤ │ │ ├──────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-46600 │ │ │ │ 1.26.6, 1.27.0-rc.3 │ golang.org/x/net/dns/dnsmessage: │
│ │ │ │ │ │ │ golang.org/x/net/dns/dnsmessage: Denial of Service via │
│ │ │ │ │ │ │ invalid DNS record parsing │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-46600 │
│ ├────────────────┤ │ │ ├──────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-56853 │ │ │ │ 1.25.13, 1.26.6, 1.27.0-rc.3 │ net/http: golang: Go net/http: Unencrypted HTTP/2 │
│ │ │ │ │ │ │ connections vulnerable to Denial of Service... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-56853 │
│ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-56858 │ │ │ │ │ html/template: golang: Go html/template: Cross-Site │
│ │ │ │ │ │ │ Scripting via pathological input │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-56858 │
│ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-56859 │ │ │ │ │ encoding/xml: golang: Go: Denial of Service via XML decoding │
│ │ │ │ │ │ │ recursion depth issue... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-56859 │
│ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-56860 │ │ │ │ │ net/url: golang: golang net/url: Denial of Service from │
│ │ │ │ │ │ │ quadratic complexity in path... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-56860 │
│ ├────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2026-56862 │ │ │ │ │ crypto/tls: golang: Golang crypto/tls: Denial of Service via │
│ │ │ │ │ │ │ indefinite KeyUpdate messages │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2026-56862 │
└─────────┴────────────────┴──────────┴────────┴───────────────────┴──────────────────────────────┴──────────────────────────────────────────────────────────────┘