Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54761Mediumgithub.com/traefik/traefik/v3: Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesCVE-2026-20706Mediumcode.gitea.io/gitea: Gitea: Token scope bypass on web archive download endpointCVE-2026-27783Mediumcode.gitea.io/gitea: Gitea: Missing repository-unit authorization on issue-template API endpointsCVE-2026-25714Mediumcode.gitea.io/gitea: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flawCVE-2026-26231Highcode.gitea.io/gitea: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repoCVE-2026-28699Highcode.gitea.io/gitea: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authenticationCVE-2026-52797Highgogs.io/gogs: Gogs: Overwriting critical files results in a denial of serviceCVE-2026-49980Criticalgithub.com/rclone/rclone: Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixCVE-2026-28744Highcode.gitea.io/gitea: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer TokensCVE-2026-54322Highgithub.com/daytonaio/daytona: Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's rolesCVE-2026-52846Mediumgithub.com/caddyserver/caddy/v2: Caddy: stripHTML template function bypassCVE-2026-52845Highgithub.com/caddyserver/caddy/v2: Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`CVE-2026-52844Highgithub.com/caddyserver/caddy/v2: Caddy: Windows `file_server` path authorization bypass via encoded backslashCVE-2026-54321Highgithub.com/daytonaio/daytona: Daytona: Public sandbox previews remain accessible for up to one hour after being made privateCVE-2026-53622HighTraefik: Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hostsCVE-2026-50135Mediumgithub.com/gohugoio/hugo: Hugo: Symlink confinement bypass in resources.GetCVE-2026-50134Mediumgithub.com/gohugoio/hugo: Hugo: security.http.urls allow-list bypass via HTTP redirectsCVE-2026-50133Mediumgithub.com/gohugoio/hugo: Hugo: XSS via text/html content filesCVE-2026-48491HighTraefik: Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypassCVE-2026-54090Highgithub.com/filebrowser/filebrowser/v2: File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter InjectionCVE-2026-54091Highgithub.com/filebrowser/filebrowser/v2: File Browser has incorrect access control for public directory shares via rule path rebasingCVE-2026-54093Mediumgithub.com/filebrowser/filebrowser/v2: File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenamesCVE-2026-54094Mediumgithub.com/filebrowser/filebrowser/v2: File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scopeCVE-2026-54092Highgithub.com/filebrowser/filebrowser/v2: File Browser has a DoS Vulnerability via Public Login APICVE-2026-54096Highgithub.com/filebrowser/filebrowser/v2: File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

Stop the waste.
Protect your environment with Kodem.