Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-52814Mediumgogs.io/gogs: Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)CVE-2026-52813Criticalgogs.io/gogs: Gogs has Path Traversal in organization name that results in RCE through Git hooksCVE-2026-52812Highgogs.io/gogs: Gogs: LFS dedupe path leaks private repo content across tenantsCVE-2026-52811Criticalgogs.io/gogs: Gogs: UploadRepoFiles writes outside repo working tree via committed parent symCVE-2026-52810Highgogs.io/gogs: Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusionCVE-2026-52809Mediumgogs.io/gogs: Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVESCVE-2026-52808Highgogs.io/gogs: Gogs's write-level collaborators can mutate admin-only repository settings via APICVE-2026-52807Mediumgogs.io/gogs: Gogs has DOM-based XSS via Milestone Name on New Issue PageCVE-2026-52806Criticalgogs.io/gogs: Gogs vulnerable to RCE via git rebase --exec argument injection in pull request mergeCVE-2026-52805Highgogs.io/gogs: Gogs has a Migration Redirect Bypass that Leads to Internal Repository TheftCVE-2026-52804Mediumgogs.io/gogs: Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode ValidationCVE-2026-52802Mediumgogs.io/gogs: Gogs has an Open Redirect via redirect_toCVE-2026-52801Highgogs.io/gogs: Gogs has the ability to import local repositories via Mirror SettingsCVE-2026-52800Highgogs.io/gogs: Gogs Vulnerable to CSRF Leading to Organization Owner TakeoverCVE-2026-52799Highgogs.io/gogs: Gogs Missing Authorization in Attachment DownloadCVE-2026-52798Highgogs.io/gogs: Gogs has Stored XSS in `.ipynb` PreviewCVE-2026-52796Lowgogs.io/gogs: Gogs has DoS in rendering issue index patternGHSA-GHMH-JHMJ-WCMFMediumgithub.com/juev/nebula-mesh: nebula-mesh's stores enrollment tokens unhashed in SQLiteCVE-2026-47267Highgogs.io/gogs: Gogs has SSRF in webhook deliveriesCVE-2026-44778Lowgithub.com/inspektor-gadget/inspektor-gadget: Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)CVE-2026-44517Mediumgithub.com/containers/buildah: Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archiveCVE-2026-41579Mediumgithub.com/opencontainers/runc: runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations CVE-2026-25119Highgogs.io/gogs: Gogs has an Authentication Bypass via Unvalidated Reverse Proxy HeadersCVE-2025-64719Mediumgogs.io/gogs: Gogs has a Denial of Service in repository/wiki file listing web pagesGHSA-6VXV-WG6J-5QWPHighgogs.io/gogs: Gogs: XSS in .ipynb files renderer due to outdated notebookjs

Stop the waste.
Protect your environment with Kodem.