Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50570Highgithub.com/fission/fission: Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node…CVE-2026-54332Mediumgithub.com/gopacket/gopacket: GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) ->…CVE-2026-54345Mediumgithub.com/gopacket/gopacket: GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)CVE-2026-54593Highpterodactyl/panel: Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionsCVE-2026-47427Highgithub.com/github/github-mcp-server: GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete HandlerGHSA-HP74-GM6M-2QM5Mediumgithub.com/pocket-id/pocket-id/backend: Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that…CVE-2026-43983Highgithub.com/pocket-id/pocket-id/backend: Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictionsCVE-2026-43871Highthrift: Apache Thrift Python, Go, PHP and Java bindings have an Infinite LoopCVE-2026-73500Highgo.etcd.io/etcd/v3: etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadlineCVE-2026-73502Mediumgithub.com/getkin/kin-openapi: kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has…CVE-2026-73499Highgo.etcd.io/etcd/v3: etcd: Watch API authorization bypass via open-ended range requestsCVE-2026-73505Highgithub.com/jandedobbeleer/oh-my-posh: Oh My Posh: Arbitrary command execution via template injection in the path segmentCVE-2026-73506Mediumgithub.com/jandedobbeleer/oh-my-posh: Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment dataCVE-2026-69160Mediumgithub.com/OpenListTeam/OpenList/v4: OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation APIGHSA-P6PH-3JX2-3337Mediumgithub.com/OpenListTeam/OpenList/v4: OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve SearchCVE-2026-73509Highgithub.com/OpenListTeam/OpenList/v4: OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversalGHSA-V6W6-358X-2433Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requestsCVE-2026-73564Highgithub.com/fatedier/frp: frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer OverflowGHSA-C534-2W9C-X7FMMediumgithub.com/zxh326/kite: Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resourcesCVE-2026-62323Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve WOPI view sessions can write files and WOPI access token secret is ignoredCVE-2026-57497Mediumgithub.com/quic-go/webtransport-go: webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown CapsulesCVE-2026-55502Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentialsCVE-2026-55499Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and…CVE-2026-55497Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the serverCVE-2026-55496Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned…

Stop the waste.
Protect your environment with Kodem.