Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55866Lowgithub.com/authzed/spicedb: SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expectedCVE-2026-55776Mediumgithub.com/openbao/openbao: OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key typesCVE-2026-55775Lowgithub.com/openbao/openbao: OpenBao's System Backend allows Unauthorized Management of the containing NamespaceCVE-2026-55774Lowgithub.com/openbao/openbao: OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808CVE-2026-55770Mediumgithub.com/openbao/openbao: OpenBao: LDAPi ldaputil (wrong escape func)CVE-2026-55187Mediumgithub.com/axllent/mailpit: Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanismsCVE-2026-55185Mediumminiflux.app/v2: Open Redirect Bypass in miniflux-v2CVE-2026-54762Mediumgithub.com/traefik/traefik/v3: Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsCVE-2026-55828Mediumgo.qbee.io/transport: go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)CVE-2026-11769Mediumgithub.com/grafana/grafana-operator/v5: Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileNameGHSA-WFQX-GJRF-G28RCriticalgithub.com/crossplane/crossplane/v2: Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tagGHSA-X845-2F78-7V36Highgithub.com/0xERR0R/blocky: Blocky DNSSEC validation bypass and validation-cache scope pollutionCVE-2026-53492Highgithub.com/containerd/containerd/v2: containerd CRI checkpoint restore CDI annotation smugglingCVE-2026-53489Highgithub.com/containerd/containerd/v2: Arbitrary host CRI log file read via symlink following in CRI checkpoint restoreCVE-2026-53488Highgithub.com/containerd/containerd: containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pullCVE-2026-50195Mediumgithub.com/containerd/containerd/v2: containerd: CRI checkpoint import allows local image tag poisoningCVE-2026-47262Mediumgithub.com/containerd/containerd/v2: containerd image-triggered runtime DoS via unbounded group parsingGHSA-R46F-3RPW-HXRVHighgithub.com/gohugoio/hugo: Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)GHSA-C3WQ-J5VH-68RCMediumgithub.com/gohugoio/hugo: Hugo: Symlink confinement bypass in os.ReadFileGHSA-Q76J-GCG9-VXC6Mediumgithub.com/gohugoio/hugo: Hugo: XSS via unescaped code-fence language in default code block rendererGHSA-Q7J3-V8QV-22VQHighgithub.com/opentofu/opentofu: OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URLGHSA-2H46-9X5W-4WF7Mediumgithub.com/entireio/cli: Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewindCVE-2026-55689Mediumgithub.com/openfga/openfga: OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unsetCVE-2026-55884Criticalgithub.com/tilt-dev/tilt: Tilt: Missing authentication on the network-exposed Tilt HUD serverCVE-2026-55883Highgithub.com/tilt-dev/tilt: Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

Stop the waste.
Protect your environment with Kodem.