go package report

Is github.com/jhaals/yopass safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      high

      severity band, no base score published

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-6r69-c6wg-7g8m, the advisory selected below

      // 1 advisories

      GHSA-6r69-c6wg-7g8m

      HIGHCVE-2026-107840

      The Prometheus metrics middleware in pkg/server/server.go used r.Method directly as a label value on request counter and duration histogram metrics. Since the mux catch-all route matches any HTTP method, an unauthenticated attacker can send requests with arbitrary method strings (e.g. curl -X "M1" http://host/), each creating new counter and histogram time series in the Prometheus registry. The registry's internal maps never evict entries.

      An attacker issuing requests with unique method values causes monotonic memory growth until the process is OOM-killed. Additionally, /metrics scrape latency degrades proportionally, eventually timing out and blinding monitoring.

      Remediation: Upgrade to 14.7.0 or later, which clamps the method label to a fixed allowlist (GET, POST, PUT, DELETE, OPTIONS, HEAD, CONNECT, TRACE) and maps everything else to other.


      Checked 2026-10-09 at 23:57 UTC. The most recent advisory here was published 2026-10-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.