Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40898Mediumgithub.com/quic-go/quic-go: quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion CVE-2026-37462Highgithub.com/osrg/gobgp/v4: GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes functionCVE-2026-48119Highgithub.com/nezhahq/nezha: Nezha's authenticated agents can forge service-monitor results for other users' servicesCVE-2026-10517Mediumgithub.com/quay/claircore: Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpointsCVE-2026-10219Mediumgithub.com/nextlevelbuilder/goclaw: GoClaw has a Command Injection issueCVE-2026-47268Mediumgithub.com/nezhahq/nezha: Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard hostCVE-2026-47203Lowgithub.com/authelia/authelia/v4: Authelia Missing Username Canonicalization in Basic Auth (LDAP)CVE-2026-47201Highgoauthentik.io: authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated userGHSA-W5PP-99CH-QJ29Mediumgithub.com/go-git/go-git/v5: go-git: Malformed Git object data may cause panics or resource exhaustionGHSA-RF84-WR5G-M3RPMediumgithub.com/metal3-io/cluster-api-provider-metal3: CAPM3 vulnerable to Cross-Namespace resource accessCVE-2026-47190Mediumgithub.com/metal3-io/ip-address-manager: IPAM controller service account granted unnecessary full access to SecretsGHSA-HFC8-W5F4-3X6MMediumgithub.com/metal3-io/ironic-standalone-operator: Ironic Standalone Operator's controller modifies user-owned resources without consentGHSA-7CWM-FPFH-RRCHMediumgithub.com/metal3-io/ironic-standalone-operator: Ironic Standalone Operator's prometheus metrics exporter bound to all interfacesCVE-2026-45742Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has a Race Condition via Multipart `downloadFrom` HandlingCVE-2026-45741Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixesCVE-2026-44829Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has path traversal in zip entry name via Windows-style separators in upload filenameCVE-2026-48501Highgithub.com/cli/cli/v2: GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and…CVE-2026-47179Highgithub.com/getarcaneapp/arcane/backend: Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include DirectivesCVE-2026-46405Mediumgithub.com/openbao/openbao: OpenBao's Kerberos Auth Method Accumulates Unaccessible TokensCVE-2026-9097Criticalgithub.com/casdoor/casdoor: Casdoor doesn't verify that a JWT used for token exchange is still activeCVE-2026-9094Criticalgithub.com/casdoor/casdoor: Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature checkCVE-2026-9096Highgithub.com/casdoor/casdoor: Casdoor doesn't enforce SAML assertion time boundsCVE-2026-9098Criticalgithub.com/casdoor/casdoor: Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequestCVE-2026-6720Highgithub.com/projectcalico/calicoctl/v3: Calico Inserts Sensitive Information into Log FileCVE-2026-9093Criticalgithub.com/casdoor/casdoor: Casdoor does not validate the AudienceRestriction element in SAML assertions

Stop the waste.
Protect your environment with Kodem.