Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:golang/github.com/golang/go/src/os

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Join the discussion

CVE-2025-0913 is a vulnerability in the Go standard library syscall package related to improper link resolution before file access. The os.OpenFile function behaved inconsistently between Unix and Windows when handling dangling symbolic links with the O_CREATE and O_EXCL flags. On Unix, it did not follow symlinks, but on Windows, it created a file at the symlink's nonexistent target location. The issue is now fixed so that OpenFile returns an error when both flags are set and the target path is a symlink.

Join the discussion

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.

Join the discussion

CVE-2025-22873 is a relative path traversal vulnerability in the Go standard library's os package that allows opening the parent directory of a defined root directory by using a filename ending with ".. /". This vulnerability permits access only to the immediate parent directory, not to higher-level ancestors or files within the parent directory. It affects Go versions up to 1.24.0-0 and has a low CVSS score of 3.8, indicating limited impact. Exploitation requires local privileges and no user interaction but can lead to limited confidentiality exposure by allowing directory traversal beyond intended boundaries. No known exploits are currently reported in the wild. European organizations using vulnerable Go versions in applications that enforce directory restrictions via os.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:golang/github.com/golang/go/src/os
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses