CVE-2018-12976: Godoc Go Doc Dot Org
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
Affected products
- Godoc Go Doc Dot Org: up to and including 2018-06-27
Published 2018-07-05. Last modified 2026-06-17.