Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54097Highgithub.com/filebrowser/filebrowser: File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefixCVE-2026-46371Mediumgithub.com/fleetdm/fleet/v4: Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpointCVE-2026-46370Mediumgithub.com/fleetdm/fleet/v4: Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpointCVE-2026-53999Highgithub.com/radius-project/radius: Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)GHSA-6VGG-XHVH-38FFLowgithub.com/juev/nebula-mesh: nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-storeCVE-2026-48154Mediumgithub.com/pilinux/gorest: gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)GHSA-9R4W-JG96-92MVMediumgithub.com/google/go-attestation: Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()CVE-2026-48113Highgithub.com/jpillora/chisel: Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData InjectionCVE-2026-11401Highgithub.com/aws/aws-advanced-go-wrapper/awssql/v2: AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instanceCVE-2026-48096Mediumgithub.com/openfga/openfga: OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision…CVE-2026-48089Highgithub.com/l3montree-dev/devguard: DevGuard has improper authorization on public assetsCVE-2026-48050Highgithub.com/basekick-labs/arc: Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSCVE-2026-48020Highgithub.com/traefik/traefik/v2: Traefik has a StripPrefix Route-Level Auth Bypass via Path NormalizationCVE-2026-47780Mediumgithub.com/free5gc/udr: free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistenceCVE-2026-47768Mediumgithub.com/juev/nebula-mesh: nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)CVE-2026-47753Mediumgithub.com/lxc/incus/v7: Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)CVE-2026-48058Mediumgithub.com/juev/nebula-mesh: nebula-mesh: Session and OIDC state cookies lack the Secure attributeCVE-2026-48025Mediumgithub.com/juev/nebula-mesh: nebula-mesh: Decrypted CA private key persists in heap after signingCVE-2026-47701Highgithub.com/open-telemetry/opentelemetry-operator: OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer authCVE-2026-47253Highgithub.com/julien040/anyquery: Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory DeletionCVE-2026-49397Mediumgithub.com/nezhahq/nezha: Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing dataCVE-2026-49396Highgithub.com/nezhahq/nezha: Nezha has cross-site GET request that can trigger stored cron commands on a victim's agentsCVE-2026-48031Criticalgithub.com/dhax/go-base: Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token ForgeryGHSA-7QJX-GP9H-65QJHighgithub.com/dexidp/dex: Dex: Token-exchange endpoint is missing AllowedConnectors enforcementCVE-2026-47735Highgithub.com/basekick-labs/arc: Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks

Stop the waste.
Protect your environment with Kodem.