cve
base
Search
Products
Trending
About
Docs
Pricing
Home
/
Products
/
azure
/
Azure Go-Ntlmssp
Azure Go-Ntlmssp vulnerabilities
1 known vulnerability affecting
azure/go-ntlmssp
.
Version
All versions
Total CVEs
1
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM
1
Vulnerabilities
Page 1 of 1
CVE-2026-32952
MEDIUM
CVSS 5.3
fixed in 0.1.1
2026-04-24
CVE-2026-32952 [MEDIUM] CWE-190 CVE-2026-32952: go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0 go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.
nvd