Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-6C87-G9PW-78FXLowgithub.com/edgelesssys/contrast: Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain…CVE-2026-49835Mediumgithub.com/sigstore/timestamp-authority/v2: Sigstore Timestamp Authority has OOM due to unbounded metric label cardinalityCVE-2026-49478Highgithub.com/sigstore/fulcio: Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token…CVE-2026-49820Mediumgo.probo.inc/probo: Probo has an open redirect bypass via path normalizationCVE-2026-50566Criticalgithub.com/fission/fission: Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creationCVE-2026-50565Mediumgithub.com/fission/fission: Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerCVE-2026-50564Criticalgithub.com/fission/fission: Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escapeCVE-2026-50563Criticalgithub.com/fission/fission: Fission Container Executor Function PodSpec Injection Leading to Node EscapeCVE-2026-50545Criticalgithub.com/fission/fission: Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverCVE-2026-49824Highgithub.com/fission/fission: Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhookCVE-2026-49823Highgithub.com/fission/fission: Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhookCVE-2026-49822Highgithub.com/fission/fission: Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillanceCVE-2026-49821Highgithub.com/fission/fission: Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltrationGHSA-7M8X-QG2J-4M3VHighgithub.com/fission/fission: Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpecGHSA-55F6-4PR5-C7M5Highgithub.com/kahiteam/kahi: Kahi has privilege-drop and socket/log permission issuesCVE-2026-44840Highgithub.com/dgraph-io/dgraph/v25: Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL QueryGHSA-WW5P-J6CJ-6MQQMediumgithub.com/nezhahq/nezha: Nezha Dashboard: DDNS and Notification credential exposure via unredacted list APICVE-2026-49338Highgo.senan.xyz/gonic: Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)CVE-2026-49339Highgo.senan.xyz/gonic: gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlistsCVE-2026-49340Highgo.senan.xyz/gonic: gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the…CVE-2026-53523Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: OAuth2 Redirect URL — Host Header InjectionCVE-2026-53522Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSCVE-2026-53519Criticalgithub.com/nezhahq/nezha: Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_keyCVE-2026-53521Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile contextCVE-2026-53520Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Stop the waste.
Protect your environment with Kodem.