Msrc Azl3 Gcc 13.2.0-7 On Azure Linux 3.0 vulnerabilities

66 known vulnerabilities affecting msrc/azl3_gcc_13.2.0-7_on_azure_linux_3.0.

Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH35MEDIUM23LOW1

Vulnerabilities

Page 1 of 4
CVE-2026-4746CRITICALCVSS 10.02026-03-10
CVE-2026-4746 [CRITICAL] CWE-787 Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton Mariner: Mariner GovTech CSG: GovTech CSG Customer Action Required: Yes
msrc
CVE-2026-27142HIGHCVSS 7.52026-03-10
CVE-2026-27142 [MEDIUM] URLs in meta content attribute actions are not escaped in html/template URLs in meta content attribute actions are not escaped in html/template Mariner: Mariner Go: Go Customer Action Required: Yes
msrc
CVE-2025-61727MEDIUMCVSS 6.52025-12-09
CVE-2025-61727 [MEDIUM] Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509 Mariner: Mariner Go: Go Customer Action Required: Yes
msrc
CVE-2025-47912HIGHCVSS 7.72025-10-14
CVE-2025-47912 [MEDIUM] Insufficient validation of bracketed IPv6 hostnames in net/url Insufficient validation of bracketed IPv6 hostnames in net/url FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2025-58189HIGHCVSS 7.52025-10-14
CVE-2025-58189 [MEDIUM] ALPN negotiation error contains attacker controlled information in crypto/tls ALPN negotiation error contains attacker controlled information in crypto/tls FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
msrc
CVE-2025-58185HIGHCVSS 7.52025-10-14
CVE-2025-58185 [MEDIUM] Parsing DER payload can cause memory exhaustion in encoding/asn1 Parsing DER payload can cause memory exhaustion in encoding/asn1 FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2025-61723HIGHCVSS 7.52025-10-14
CVE-2025-61723 [HIGH] Quadratic complexity when parsing some invalid inputs in encoding/pem Quadratic complexity when parsing some invalid inputs in encoding/pem FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source li
msrc
CVE-2025-61725MEDIUMCVSS 6.52025-10-14
CVE-2025-61725 [HIGH] Excessive CPU consumption in ParseAddress in net/mail Excessive CPU consumption in ParseAddress in net/mail FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2025-58187MEDIUMCVSS 5.32025-10-14
CVE-2025-58187 [HIGH] Quadratic complexity when checking name constraints in crypto/x509 Quadratic complexity when checking name constraints in crypto/x509 FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librarie
msrc
CVE-2025-22874HIGHCVSS 7.52025-06-10
CVE-2025-22874 [HIGH] Usage of ExtKeyUsageAny disables policy validation in crypto/x509 Usage of ExtKeyUsageAny disables policy validation in crypto/x509 FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2025-4673MEDIUMCVSS 6.82025-06-10
CVE-2025-4673 [MEDIUM] Sensitive headers not cleared on cross-origin redirect in net/http Sensitive headers not cleared on cross-origin redirect in net/http FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librari
msrc
CVE-2025-22871HIGHCVSS 8.22025-04-08
CVE-2025-22871 [CRITICAL] Request smuggling due to acceptance of invalid chunked data in net/http Request smuggling due to acceptance of invalid chunked data in net/http FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open s
msrc
CVE-2024-34158HIGHCVSS 7.52024-09-10
CVE-2024-34158 [HIGH] CWE-674 Stack exhaustion in Parse in go/build/constraint Stack exhaustion in Parse in go/build/constraint FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2024-34156HIGHCVSS 7.52024-09-10
CVE-2024-34156 [HIGH] Stack exhaustion in Decoder.Decode in encoding/gob Stack exhaustion in Decoder.Decode in encoding/gob FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compo
msrc
CVE-2024-34155MEDIUMCVSS 4.32024-09-10
CVE-2024-34155 [MEDIUM] Stack exhaustion in all Parse functions in go/parser Stack exhaustion in all Parse functions in go/parser FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-24531CRITICALCVSS 9.82024-07-09
CVE-2023-24531 [CRITICAL] Output of "go env" does not sanitize values in cmd/go Output of "go env" does not sanitize values in cmd/go FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc
CVE-2024-24791HIGHCVSS 7.52024-07-09
CVE-2024-24791 [HIGH] Denial of service due to improper 100-continue handling in net/http Denial of service due to improper 100-continue handling in net/http FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
msrc
CVE-2024-24790CRITICALCVSS 9.82024-06-11
CVE-2024-24790 [CRITICAL] Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versio
msrc
CVE-2024-24789MEDIUMCVSS 5.32024-06-11
CVE-2024-24789 [MEDIUM] Mishandling of corrupt central directory record in archive/zip Mishandling of corrupt central directory record in archive/zip FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-24787MEDIUMCVSS 6.42024-05-14
CVE-2024-24787 [MEDIUM] Arbitrary code execution during build on Darwin in cmd/go Arbitrary code execution during build on Darwin in cmd/go FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc