Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-47726Highgithub.com/juev/nebula-mesh: nebula-mesh: GET /api/v1/audit-log discloses all entries to any operatorCVE-2026-47725Highgithub.com/juev/nebula-mesh: nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpointsCVE-2026-47724Criticalgithub.com/juev/nebula-mesh: nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalationCVE-2026-47723Highgithub.com/juev/nebula-mesh: nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)CVE-2026-47722Highgithub.com/juev/nebula-mesh: nebula-mesh: Host advanced overrides allow YAML injection into agent config.ymlCVE-2026-47252Criticalgithub.com/julien040/anyquery/plugins/chrome: Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome PluginCVE-2026-11481Lowgithub.com/yoanbernabeu/grepai: grepai Uses a Broken or Risky Cryptographic AlgorithmCVE-2026-11479Lowgithub.com/yoanbernabeu/grepai: grepai Uses a Broken or Risky Cryptographic AlgorithmCVE-2026-11465Lowgithub.com/songquanpeng/one-api: songquanpeng one-api has an issue that results in business logic errorsCVE-2026-52878Highgithub.com/klever-io/klever-go: Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData)…CVE-2026-52880Highgithub.com/klever-io/klever-go: klever-go: REST API slow-header connection exhaustion via Gin Engine.RunCVE-2026-52879Highgithub.com/klever-io/klever-go: klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoSCVE-2026-49343Mediumgithub.com/klever-io/klever-go: Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoSCVE-2026-47680Mediumgithub.com/fluxcd/source-controller: Source controller: Improper path handling allows traversalCVE-2026-47249Highgithub.com/klever-io/klever-go: Klever-Go KVM: Hash-array amplification in P2P resolver request handlingCVE-2026-45726Highgithub.com/siderolabs/omni: Omni: Reader-level users can retrieve imported cluster CA keys via ResourceServiceCVE-2026-45723Lowgithub.com/siderolabs/omni: Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematicCVE-2026-45720Highgithub.com/siderolabs/omni: Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session tokenCVE-2026-47703Mediumgithub.com/AdguardTeam/AdGuardHome: AdGuard Home: DoQ-to-UDP State Reduction and Source-Port OracleCVE-2026-8462Mediumgithub.com/openmeterio/openmeter: OpenMeter: SQL injection through meter creationCVE-2026-10814Lowgithub.com/milvus-io/milvus: milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgeryCVE-2026-47671Mediumgithub.com/nhost/nhost: Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secretsGHSA-74M6-4HJP-7226Highgithub.com/klever-io/klever-go: Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)CVE-2026-47215Mediumgithub.com/sylabs/singularity/v4: Singluarity: Incorrect path matching for 'limit container paths' directiveCVE-2026-45730Highgithub.com/nuclio/nuclio: Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project

Stop the waste.
Protect your environment with Kodem.