Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53495Mediumgithub.com/containerd/containerd/v2: containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of ServiceCVE-2025-58363Mediumgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation EndpointCVE-2025-24979Mediumgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper: SSRF in External ServiceCVE-2025-24978Lowgithub.com/lf-edge/ekuiper/v2: LF Edge eKuiper: Self-XSS in External Service CreationCVE-2026-84445Highgoogle.golang.org/grpc: gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headersCVE-2026-84303Mediumgoogle.golang.org/grpc: gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasionCVE-2026-71494Mediumgithub.com/infracost/infracost: Infracost: Terraform Cloud and registry token disclosure via unvalidated hostnameCVE-2026-71493Mediumgithub.com/infracost/infracost: Infracost: Arbitrary file read via config-template readFile symlink traversalCVE-2026-73087Lowgithub.com/amir20/dozzle: Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcherCVE-2026-73294Criticalgithub.com/semaphoreui/semaphore: Semaphore U: OS Command InjectionCVE-2026-60004Criticalgitea.dev: Gitea: Remote Code Execution via diffpatch Git Hook InstallationCVE-2026-72789Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully…CVE-2026-72790Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by…GHSA-57V5-WQX3-CGJ4Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by…CVE-2026-73842Criticalgithub.com/openchoreo/openchoreo: OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and…CVE-2026-72792Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the passwordCVE-2026-72793Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips,…CVE-2026-72795Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document…CVE-2026-72794Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConfCVE-2026-72796Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts…CVE-2026-72797Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readersCVE-2026-72798Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columnsCVE-2026-72799Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readersCVE-2026-72800Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration…CVE-2026-72801Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline…

Stop the waste.
Protect your environment with Kodem.