Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55882Highgithub.com/tilt-dev/tilt: Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD serverCVE-2026-10720Mediumgithub.com/canonical/microceph/microceph: Canonical MicroCeph: path traversal issue in the remote-import APCVE-2026-54319Mediumgithub.com/daytonaio/daytona: Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeCVE-2026-11719Highgithub.com/googleapis/mcp-toolbox: MCP Toolbox for Databases: authenticated authorization bypassCVE-2026-11718Criticalgithub.com/googleapis/mcp-toolbox: googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)CVE-2026-11717Criticalgithub.com/googleapis/mcp-toolbox: googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)CVE-2026-55170Lowgithub.com/openfga/openfga: OpenFGA Improper Policy EnforcementCVE-2026-55701Mediumgithub.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authenticationCVE-2026-47256Mediumgithub.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter: opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged…CVE-2026-55686Mediumgithub.com/containers/podman/v5: Podman: WORKDIR symlink traversal vulnerabilityCVE-2026-57209Highgithub.com/dadrus/heimdall: Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy ModeCVE-2026-57210Highhttps://github.com/dadrus/heimdall: Heimdall: IP Spoofing via Unvalidated Forwarding HeadersCVE-2026-55669Mediumgithub.com/zitadel/zitadel: ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP ProviderCVE-2026-56664Mediumgithub.com/zitadel/zitadel: ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP ProviderCVE-2026-55672Highgithub.com/zitadel/zitadel: ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)CVE-2026-55670Lowgithub.com/zitadel/zitadel: ZITADEL: Cross-Tenant User Leakage via Recycled IdentifiersCVE-2026-55887Highgithub.com/docker/mcp-gateway: Docker MCP Gateway: Argument injection via OCI image label YAMLCVE-2026-55229Highgithub.com/gotenberg/gotenberg/v8: Gotenberg: SSRF via LibreOffice document processingCVE-2026-55671Lowgithub.com/zitadel/zitadel: ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP ComponentsCVE-2026-55636Mediumgithub.com/projectcapsule/capsule: Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotectedCVE-2026-25779Mediumgithub.com/go-gitea/gitea: Gitea: Open Redirect via redirect_toCVE-2026-28737Highcode.gitea.io/gitea: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File ViewerCVE-2026-24791Highcode.gitea.io/gitea: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routesCVE-2026-22555Highcode.gitea.io/gitea: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret ExfiltrationCVE-2026-54324Mediumgithub.com/daytonaio/daytona: Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

Stop the waste.
Protect your environment with Kodem.