Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-9090Criticalgithub.com/casdoor/casdoor: Casdoor has an authentication bypassCVE-2026-41184Mediumgithub.com/projectcalico/calico: Calico Inserts Sensitive Information into Log FileCVE-2026-9091Mediumgithub.com/casdoor/casdoor: Casdoor allows users to bypass configured MFA requirementsCVE-2026-41185Mediumgithub.com/projectcalico/calico: Calico Inserts Sensitive Information into Log FileCVE-2026-46358Mediumgithub.com/openbao/openbao: OpenBao's Inline Auth Incorrectly Redacted HeadersCVE-2026-45808Highgithub.com/openbao/openbao: OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACLCVE-2026-45287Lowgo.opentelemetry.io/otel/schema/v1.1: opentelemetry-go's Schema ParseFile leaks file descriptors on each parseCVE-2026-41178Mediumgo.opentelemetry.io/otel/baggage: opentelemetry-go's baggage parsing no longer caps raw header lengthCVE-2026-22872Mediumgithub.com/projectcapsule/capsule: Capsule TenantResource RawItems Cluster-Scoped Resource Creation VulnerabilityCVE-2026-30963Lowgithub.com/projectcapsule/capsule: Capsule Namespace Hijacking via subresourceCVE-2026-9804Highkubevirt.io/kubevirt: KubeVirt has a Link Following issueCVE-2026-9739Criticalgithub.com/googleapis/mcp-toolbox: MCP Toolbox for Databases vulnerable to DNS rebinding attacksCVE-2026-47243Highgithub.com/kata-containers/kata-containers: Kata guest escape: runtime-rs guest-root to host-root escape via virtiofsCVE-2026-44982Highgithub.com/crowdsecurity/crowdsec: CrowdSec AppSec silently drops request body for chunked / HTTP-2 requestsCVE-2026-44981Mediumgithub.com/crowdsecurity/crowdsec: CrowdSec LAPI: Denial of Service via Unbounded Gzip DecompressionCVE-2026-36045Highgithub.com/sipeed/picoclaw: picoclaw is vulnerable to OS command injection via the ExecTool componentCVE-2026-44210Mediumgithub.com/kata-containers/kata-containers: Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod AnnotationsCVE-2026-7374Criticalkubevirt.io/kubevirt: KubeVirt has a Link Following vulnerabilityCVE-2026-4915Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processingCVE-2026-9300Lowgithub.com/omec-project/amf: omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2026-9301Lowgithub.com/omec-project/amf: omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2026-9299Lowgithub.com/omec-project/amf: omec-project amf Vulnerable to Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2026-28735Mediumgithub.com/mattermost/mattermost-server: Mattermost allows authenticated users to gain access to private repositoriesCVE-2026-25680Mediumgolang.org/x/net: Go Net HTML parser is vulnerable to denial of serviceCVE-2026-5308Highgithub.com/mattermost/mattermost-server: Mattermost doesn't enforce request body size limits on plugin HTTP endpoints

Stop the waste.
Protect your environment with Kodem.