CVE-2024-55885: Beego

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with SHA256.

Affected products

  • Beego Beego: before 2.3.4 (fixed in 2.3.4)

Published 2024-12-12. Last modified 2026-06-17.