Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-3473Highgithub.com/mattermost/mattermost-server: Mattermost doesn't validate file ownership and access controlCVE-2026-5740Highgithub.com/mattermost/mattermost-server: Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocationCVE-2026-4646Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't validate user-supplied input in API request handlersCVE-2026-4635Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't archive the channel before removing persistent notificationsCVE-2026-3636Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't sanitize team member data when returned via API to users without elevated permissionsCVE-2026-5755Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memoryCVE-2026-47124Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated membersCVE-2026-46716Criticalgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronCVE-2026-47125Highgithub.com/getarcaneapp/arcane/backend: Arcane: Missing admin authorization on global variables endpointCVE-2026-47120Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)CVE-2026-46717Highgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notificationCVE-2026-48777Criticalgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directoryCVE-2026-46703Criticalboxlite: Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the HostCVE-2026-46695Criticalboxlite: BoxLite: Permission Bypass Allows Modification of Read-Only FilesCVE-2026-46680Highgithub.com/containerd/containerd: containerd user ID handling bypass allows runAsNonRoot evasionCVE-2026-46668Lowgithub.com/authzed/spicedb: SpiceDB: Caveat structures with nested lists can result in improper cache reuseCVE-2026-46618Mediumgithub.com/fission/fission: Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary…CVE-2026-46617Highgithub.com/fission/fission: Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code…CVE-2026-46614Criticalgithub.com/fission/fission: Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTriggerCVE-2026-46612Highgithub.com/fission/fission: Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archivesGHSA-763J-3P5V-JFC6Lowgithub.com/mvt-project/androidqf: androidqf: APK download Path Traversal in device APK pathsGHSA-JF2Q-463C-6F52Lowgithub.com/mvt-project/androidqf: androidqf: Zip entry Name Injection in APK bundle (Zip Slip for zip consumers)CVE-2026-46403Mediumgithub.com/klever-io/klever-go: Klever-Go KVM read-only execution can commit contract delete and upgrade side effectsCVE-2026-45760Highgithub.com/apache/camel-k/v2: Apache Camel K: Kubernetes namespace authorized users can create a Build resourceCVE-2026-4858Highgithub.com/mattermost/mattermost-server: Mattermost has a Path Traversal issue

Stop the waste.
Protect your environment with Kodem.