Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-39834Criticalgolang.org/x/crypto: golang.org/x/crypto vulnerable to infinite loop on large channel writesCVE-2026-39831Criticalgolang.org/x/crypto: golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassedCVE-2026-39829Highgolang.org/x/crypto: golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoSCVE-2026-39830Criticalgolang.org/x/crypto: golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responsesCVE-2026-39827Mediumgolang.org/x/crypto: golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoSCVE-2026-39835Mediumgolang.org/x/crypto: golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flowCVE-2026-39828Mediumgolang.org/x/crypto: golang.org/x/crypto vulnerable to invoking bypass of certificate restrictionsCVE-2026-46597Highgolang.org/x/crypto: golang.org/x/crypto: Invoking byte arithmetic causes underflow and panicCVE-2026-39832Criticalgolang.org/x/crypto: golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keysCVE-2026-39833Criticalgolang.org/x/crypto: golang.org/x/crypto doesn't enforce invoking key constraintsCVE-2026-46598Mediumgolang.org/x/crypto: golang.org/x/crypto: Invoking pathological inputs can lead to client panicCVE-2026-48702Highgithub.com/sigstore/rekor: Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing LogicCVE-2026-48529Mediumgithub.com/github/github-mcp-server: GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusionGHSA-3FXJ-6JH8-HVHXMediumgithub.com/go-chi/chi/v5/middleware: chi Has an IP Spoofing Vulnerability in `middleware.RealIP`GHSA-RJR7-JGGH-PGCPHighgithub.com/go-chi/chi/middleware: chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For headerGHSA-9G5Q-2W5X-HMXFHighgithub.com/go-chi/chi/middleware: chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` ResolutionGHSA-R4V7-6WCG-GHJ5Mediumgithub.com/gtsteffaniak/filebrowser: FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force AttacksCVE-2026-53541Mediumgithub.com/OliveTin/OliveTin: OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input FilteringCVE-2026-48709Lowgithub.com/OliveTin/OliveTin: OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument EnumerationCVE-2026-48708Highgithub.com/OliveTin/OliveTin: OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command ContaminationGHSA-WCMJ-X466-56MMMediumgithub.com/opentofu/opentofu: OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working treeCVE-2026-48496Mediumgo.opentelemetry.io/ebpf-profiler: opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agentCVE-2026-48126Highgithub.com/xyproto/algernon: Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dirCVE-2026-52816Mediumgogs.io/gogs: Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSCVE-2026-52815Mediumgogs.io/gogs: Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

Stop the waste.
Protect your environment with Kodem.