Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55502Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentialsCVE-2026-55499Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and…CVE-2026-55497Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the serverCVE-2026-55496Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned…CVE-2026-55495Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner AccountGHSA-R277-6W6Q-XMQWCriticalgithub.com/getkin/kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc DefaultGHSA-GCJH-H69Q-9W9GMediumgithub.com/google/cel-go: cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTagGHSA-464C-974J-9XM6Lowaws-cdk-lib: AWS CDK CodeBuild S3 Log Encryption Boolean InversionGHSA-HRXH-6V49-42GFHighgoogle.golang.org/grpc: gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesCVE-2026-20779Highcode.gitea.io/gitea: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surfaceCVE-2026-58429Mediumcode.gitea.io/gitea: Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission EndpointsCVE-2026-59765Mediumcode.gitea.io/gitea: Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataCVE-2026-58511Lowcode.gitea.io/gitea: Gitea: Webhook Authorization Header Returned in Plaintext via APICVE-2026-57897Mediumcode.gitea.io/gitea: Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIsCVE-2026-58510Mediumcode.gitea.io/gitea: Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateCVE-2026-58431Mediumgitea.dev: Gitea: Public-only API token restriction is not enforced on team API routesCVE-2026-58427Mediumgitea.dev: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145CVE-2026-58422Highcode.gitea.io/gitea: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsCVE-2026-58419Highcode.gitea.io/gitea: Gitea: Notification API leaks private issue metadata after access revocationCVE-2026-25038Highcode.gitea.io/gitea: Gitea: Unauthorized Access to Labels of Private OrganizationsCVE-2026-27775Highcode.gitea.io/gitea: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository WriteCVE-2026-24451Highcode.gitea.io/gitea: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to PrivateCVE-2026-58314Highcode.gitea.io/gitea: Gitea: Two SSRF findingsCVE-2026-58436Highcode.gitea.io/gitea: Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requestsCVE-2026-56657Mediumcode.gitea.io/gitea: Gitea SSH Key Parser Denial of Service

Stop the waste.
Protect your environment with Kodem.