Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-4055Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost has an Incorrect Authorization issueGHSA-PXH5-6RRC-8RJVLowgithub.com/opentofu/opentofu: OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled serverCVE-2026-46431Mediumgithub.com/xyproto/algernon: Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *CVE-2026-46430Mediumgithub.com/xyproto/algernon: Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOSCVE-2026-46415Highpkg.jsn.cam/caddy-defender: Caddy Defender trusted proxy client IP bypassCVE-2026-46410Highgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum: unauthenticated user share share info CVE-2026-46378Highgithub.com/tomwright/dasel/v3: Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literalCVE-2026-46377Highgithub.com/tomwright/dasel/v3: Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted stringCVE-2026-46354Criticalgithub.com/coder/coder/v2: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftCVE-2026-45796Mediumgithub.com/coder/coder/v2: Coder: Unauthenticated SSRF via Azure Instance Identity EndpointGHSA-G53W-W6MJ-HRPPCriticalgithub.com/Kuadrant/mcp-gateway: MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" pathCVE-2026-45803Lowgithub.com/cli/cli/v2: GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injectionGHSA-GX7W-56W6-G48XMediumgithub.com/caddyserver/caddy/v2: Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path MatchingGHSA-WWHQ-W58M-W29CMediumgithub.com/caddyserver/caddy/v2: Caddy CVE-2026-30852 Fix BypassGHSA-M23H-6MWM-39M8Mediumgithub.com/kong/kubernetes-ingress-controller/v3: Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing…GHSA-3278-C88V-XRH4Mediumgithub.com/kong/kubernetes-ingress-controller/v2: Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpointCVE-2026-45695Criticalgithub.com/kopia/kopia: Kopia: RCE via SSH ProxyCommand InjectionGHSA-4GPH-2HHR-5MWGMediumgithub.com/envoyproxy/ai-gateway: Envoy AI Proxy - MCP Message Smuggling VulnerabilityCVE-2026-45738Highgithub.com/argoproj/argo-cd/v3: Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationCVE-2026-45737Mediumgithub.com/argoproj/argo-cd/v3: Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsCVE-2026-45713Highgithub.com/axllent/mailpit: Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizesCVE-2026-45712Mediumgithub.com/axllent/mailpit: Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)CVE-2026-45711Mediumgithub.com/axllent/mailpit: Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDsCVE-2026-45709Mediumgithub.com/axllent/mailpit: Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialerCVE-2026-45692Mediumgithub.com/caddyserver/caddy/v2: Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

Stop the waste.
Protect your environment with Kodem.