Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54910Highgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesCVE-2026-54908Mediumgithub.com/pion/dtls/v3: Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageCVE-2026-54909Mediumgithub.com/pion/stun/v3: Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributeCVE-2026-54787Lowgithub.com/sigstore/sigstore-go: sigstore-go fails to check signature timestamps against a signing key's validity periodCVE-2026-53551Mediumgithub.com/free5gc/free5gc: free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failureCVE-2026-54725Criticalgithub.com/bank-vaults/vault-secrets-webhook: vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide…CVE-2026-65835Mediumgithub.com/projectcapsule/capsule: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation…CVE-2026-65834Mediumgithub.com/projectcapsule/capsule: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requestsCVE-2026-52856Highgithub.com/pterodactyl/wings: Wings: Maliciously crafted packet during SFTP connection handshake causes denial of serviceCVE-2026-52855Criticalgithub.com/pterodactyl/wings: Wings exposes node configuration secrets through egg configuration-file templatingCVE-2026-52857Mediumgithub.com/pterodactyl/wings: Wings: Maliciously or erroneously created parsed config files can cause wings process to OOMCVE-2026-67438Mediumgithub.com/OliveTin/OliveTin: OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety CheckCVE-2026-67439Mediumgithub.com/OliveTin/OliveTin: OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action OutputCVE-2026-67437Highgithub.com/OliveTin/OliveTin: OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)GHSA-XVG2-CGV6-6H7VHighgithub.com/tinfoil-factory/netfoil: netfoil: Incorrect block responses could lead to localhost trafficCVE-2026-54680Criticalgithub.com/kube-logging/logging-operator: Logging operator has Fluentd configuration injection that allows remote code executionCVE-2026-54693Highgithub.com/zitadel/zitadel: ZITADEL Users Can Self-Verify Email/Phone via APICVE-2026-54735Criticalgithub.com/prebid/prebid-server/v4: prebid-server's request forgery vulnerability allows for possible host environment data extractionCVE-2026-66064Mediumgithub.com/patrickhener/goshs/v2: goshs has ACL Bypass & Path TraversalCVE-2026-54650Highgithub.com/bablilayoub/openhole: openhole-server vulnerable to path traversal via URL-decoded request pathCVE-2026-54638Highgithub.com/gotd/td: td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.DecodeCVE-2026-66063Mediumgoshs.de/goshs/v2: goshs has a Path Traversal issueCVE-2026-64863Criticalgoshs.de/goshs/v2: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwriteCVE-2026-54719Highgithub.com/patrickhener/goshs: goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)CVE-2026-62325Criticalgithub.com/patrickhener/goshs/v2: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Stop the waste.
Protect your environment with Kodem.