Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
A race condition vulnerability exists in the Go standard library net/http package's HTTP/2 server implementation. The issue arises from concurrent unsynchronized access to the HPACK encoder by two goroutines: one encoding HEADERS frames and another modifying the header table size from SETTINGS frames. A malicious client can exploit this by repeatedly sending requests while changing the header table size, causing the server to crash. Join the discussion | CVE Database V5 | 10/08/2026, 22:54:00 UTC Added: 10/08/2026, 23:04:06 UTC |
CVE-2026-94439 is a vulnerability in the Go standard library's net/http package where an HTTP server handler improperly continues to read and serve HTTP requests after sending a 2xx response to an HTTP/1 CONNECT request without hijacking the connection. This behavior violates the expected protocol semantics because a 2xx response to an HTTP/1 CONNECT request should convert the connection into a tunnel, and the server should not treat it as continuing HTTP traffic. The issue can lead to inconsistent interpretation of HTTP requests between the server and intermediate proxies, potentially enabling HTTP request smuggling. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:59 UTC Added: 10/08/2026, 23:04:04 UTC |
0 CVE-2026-78663 is a vulnerability in the Go standard library net/http package involving HTTP/2 server flow control. The server can incorrectly refund connection-level flow control credits twice for the same data when a client resets a stream and when the request handler reads buffered data. This allows a malicious client to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection), although total buffered data remains constrained by other limits. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:59 UTC Added: 10/08/2026, 23:04:03 UTC |
0 CVE-2026-78669 is a vulnerability in the Go standard library net/http package where a malicious HTTP/2 peer can cause excessive CPU usage by opening many streams and sending numerous small SETTINGS frames with SETTINGS_INITIAL_WINDOW_SIZE values. This leads to asymmetric resource consumption, potentially degrading client or server performance. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:59 UTC Added: 10/08/2026, 23:04:04 UTC |
CVE-2026-78660 is a vulnerability in the Go standard library net/http package involving inconsistent interpretation of HTTP requests, specifically HTTP request/response smuggling. The HTTP/2 implementation in Go has historically been lax about malformed framing-related headers, which do not affect HTTP/2 framing but can be forwarded to HTTP/1 clients when acting as a reverse proxy. If the HTTP/1 client also does not strictly validate these headers, this can lead to response smuggling. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:59 UTC Added: 10/08/2026, 23:04:03 UTC |
0 CVE-2026-78667 is a vulnerability in the Go standard library net/http package where parsing a Range header with many small ranges can cause excessive CPU consumption in FileServer(FS), ServeContent, and ServeFile(FS). This is due to allocation of resources without limits or throttling. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:59 UTC Added: 10/08/2026, 23:04:04 UTC |
0 CVE-2026-94440 is a vulnerability in the Go standard library's net/textproto package where parsing a multipart form can bypass memory limits, allowing an arbitrarily long line to be read into memory if the remaining limit at the start of a part is less than 400 bytes. This can lead to uncontrolled resource allocation. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:58 UTC Added: 10/08/2026, 23:04:04 UTC |
0 CVE-2026-97031 is a vulnerability in the Go standard library's crypto/tls package involving asymmetric resource consumption. It arises from allowing multiple ECH outer extension references, which is disallowed by RFC 9849. A client could previously send a crafted packet with multiple references, causing memory exhaustion on the server. The issue is now mitigated by rejecting such malformed packets, preventing memory amplification. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:58 UTC Added: 10/08/2026, 23:04:06 UTC |
CVE-2026-56866 is a vulnerability in the Go standard library net/http package involving inconsistent interpretation of HTTP/1 CONNECT requests with a non-empty body. The http.Transport component writes the request body directly without framing, which can cause connection desynchronization if the server rejects the CONNECT request. This may lead to cross-user response poisoning in reverse proxies that reuse shared Transport connections. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:58 UTC Added: 10/08/2026, 23:04:03 UTC |
0 CVE-2026-56857 is a vulnerability in the Go standard library's os package affecting Windows systems. It involves insecure operations on Windows junctions or mount points during directory creation. Specifically, when Root.Mkdir or Root.MkdirAll targets a junction pointing to an empty location, a directory can be created at the junction target even if it lies outside the intended root directory. This issue only occurs when the last path component is a junction, not for nested paths beyond the junction. The vulnerability affects Go versions from 0 up to but excluding 1.26.9, and from 1.27.0 up to but excluding 1.27.2. Join the discussion | CVE Database V5 | 10/08/2026, 22:53:58 UTC Added: 10/08/2026, 23:04:03 UTC |
Showing 1 to 10 of 18076 results