Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037453
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

A race condition vulnerability exists in the Go standard library net/http package's HTTP/2 server implementation. The issue arises from concurrent unsynchronized access to the HPACK encoder by two goroutines: one encoding HEADERS frames and another modifying the header table size from SETTINGS frames. A malicious client can exploit this by repeatedly sending requests while changing the header table size, causing the server to crash.

Join the discussion

CVE-2026-94439 is a vulnerability in the Go standard library's net/http package where an HTTP server handler improperly continues to read and serve HTTP requests after sending a 2xx response to an HTTP/1 CONNECT request without hijacking the connection. This behavior violates the expected protocol semantics because a 2xx response to an HTTP/1 CONNECT request should convert the connection into a tunnel, and the server should not treat it as continuing HTTP traffic. The issue can lead to inconsistent interpretation of HTTP requests between the server and intermediate proxies, potentially enabling HTTP request smuggling.

Join the discussion

CVE-2026-78663 is a vulnerability in the Go standard library net/http package involving HTTP/2 server flow control. The server can incorrectly refund connection-level flow control credits twice for the same data when a client resets a stream and when the request handler reads buffered data. This allows a malicious client to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection), although total buffered data remains constrained by other limits.

Join the discussion

CVE-2026-78669 is a vulnerability in the Go standard library net/http package where a malicious HTTP/2 peer can cause excessive CPU usage by opening many streams and sending numerous small SETTINGS frames with SETTINGS_INITIAL_WINDOW_SIZE values. This leads to asymmetric resource consumption, potentially degrading client or server performance.

Join the discussion

CVE-2026-78660 is a vulnerability in the Go standard library net/http package involving inconsistent interpretation of HTTP requests, specifically HTTP request/response smuggling. The HTTP/2 implementation in Go has historically been lax about malformed framing-related headers, which do not affect HTTP/2 framing but can be forwarded to HTTP/1 clients when acting as a reverse proxy. If the HTTP/1 client also does not strictly validate these headers, this can lead to response smuggling.

Join the discussion

CVE-2026-78667 is a vulnerability in the Go standard library net/http package where parsing a Range header with many small ranges can cause excessive CPU consumption in FileServer(FS), ServeContent, and ServeFile(FS). This is due to allocation of resources without limits or throttling.

Join the discussion

CVE-2026-94440 is a vulnerability in the Go standard library's net/textproto package where parsing a multipart form can bypass memory limits, allowing an arbitrarily long line to be read into memory if the remaining limit at the start of a part is less than 400 bytes. This can lead to uncontrolled resource allocation.

Join the discussion

CVE-2026-97031 is a vulnerability in the Go standard library's crypto/tls package involving asymmetric resource consumption. It arises from allowing multiple ECH outer extension references, which is disallowed by RFC 9849. A client could previously send a crafted packet with multiple references, causing memory exhaustion on the server. The issue is now mitigated by rejecting such malformed packets, preventing memory amplification.

Join the discussion

CVE-2026-56866 is a vulnerability in the Go standard library net/http package involving inconsistent interpretation of HTTP/1 CONNECT requests with a non-empty body. The http.Transport component writes the request body directly without framing, which can cause connection desynchronization if the server rejects the CONNECT request. This may lead to cross-user response poisoning in reverse proxies that reuse shared Transport connections.

Join the discussion

CVE-2026-56857 is a vulnerability in the Go standard library's os package affecting Windows systems. It involves insecure operations on Windows junctions or mount points during directory creation. Specifically, when Root.Mkdir or Root.MkdirAll targets a junction pointing to an empty location, a directory can be created at the junction target even if it lies outside the intended root directory. This issue only occurs when the last path component is a junction, not for nested paths beyond the junction. The vulnerability affects Go versions from 0 up to but excluding 1.26.9, and from 1.27.0 up to but excluding 1.27.2.

Join the discussion

Showing 1 to 10 of 18076 results

Page 1 of 1808
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses