Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-58196Lowgithub.com/stacklok/toolhive: ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)CVE-2026-50285Highgithub.com/pomerium/pomerium: Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE CallbackCVE-2026-50274Highgithub.com/DataDog/dd-trace-go: dd-trace-go: Improper parsing of W3C baggage headers may lead to DoSCVE-2026-54495Mediumgithub.com/open-feature/open-feature-operator: open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant…CVE-2026-54452Mediumgithub.com/doyensec/safeurl: safeurl is Missing IPv6 CIDR Ranges in BlocklistCVE-2026-54450Lowgithub.com/stacklok/toolhive: ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gatewayCVE-2026-61549Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backendGHSA-7RX3-5WX3-5V76Highgithub.com/forgekeep/nebula-mesh: Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`CVE-2026-61699Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Certificate revocation is never enforced at the meshCVE-2026-55513Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokensCVE-2026-55512Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingCVE-2026-54629Highgithub.com/julien040/anyquery: Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeCVE-2026-53603Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Operator session tokens stored in plaintext in the databaseCVE-2026-53604Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: CA private key not zeroized on web mobile-bundle error pathsCVE-2026-54628Highgithub.com/julien040/anyquery: Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server ModeGHSA-MQXV-9RM6-W8QCHighgithub.com/lin-snow/ech0: Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.MiddlewareCVE-2026-54448Highgithub.com/aquasecurity/trivy: Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parserGHSA-PQG7-V6WH-3PFPHighgithub.com/almeidapaulopt/tsdproxy: TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend servicesCVE-2026-50158Highgithub.com/eat-pray-ai/yutu: yutu: Arbitrary File Write via MCP `caption-download` ToolCVE-2026-50141Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonationCVE-2026-50006Criticalgithub.com/julien040/anyquery: Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeCVE-2026-50125Highgithub.com/StacklokLabs/mkp: MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory ExhaustionCVE-2026-50018Mediumgithub.com/SpectoLabs/hoverfly: Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve ActionsCVE-2026-50013Highgithub.com/SpectoLabs/hoverfly: Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff ModeCVE-2026-54250Mediumgithub.com/k3s-io/k3s: K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

Stop the waste.
Protect your environment with Kodem.