Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45781Lowgithub.com/modelcontextprotocol/registry: MCP Registry: OCI validator skips ownership check on upstream rate limitsCVE-2026-45576Highgithub.com/openziti/zrok/v2: zrok copy writes attacker-controlled WebDAV paths outside the destination rootCVE-2026-45571Mediumgithub.com/go-git/go-git/v5: go-git: Crafted repositories may modify main and submodule .git directoriesCVE-2025-70950Highgithub.com/itang/gohttp: gohttp is vulnerable to directory traversal via a crafted requestCVE-2026-45570Lowgithub.com/go-git/go-git/v5: go-git: Improper single-quote escaping in go-git SSH transportGHSA-9V4J-7G44-QCQWMediumgithub.com/xyproto/algernon: Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authenticationCVE-2026-45721Criticalgithub.com/xyproto/algernon: Algernon: handler.lua discovery walks parent directories above the server rootCVE-2026-45728Highgithub.com/xyproto/algernon: Algernon: Single-file mode unconditionally enables debug modeCVE-2026-45686Highgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBICVE-2026-45685Highgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messagesCVE-2026-45684Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffersCVE-2026-45682Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removalsCVE-2026-45683Lowgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosureCVE-2026-45681Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB sizeCVE-2026-45680Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPUCVE-2026-45678Highgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloadsCVE-2026-45679Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messagesCVE-2026-45676Mediumgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agentCVE-2026-42306Highgithub.com/docker/docker: Docker: Race condition in docker cp allows bind mount redirection to host pathCVE-2026-41568Mediumgithub.com/docker/docker: Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swapCVE-2026-41567Highgithub.com/moby/moby/v2: Docker: `PUT /containers/{id}/archive` executes container binary on the hostCVE-2026-45327Highgithub.com/DatanoiseTV/tinyice: TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injectionCVE-2026-45298Highgithub.com/amir20/dozzle: Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)CVE-2026-46385Highgithub.com/iskorotkov/avro/v2: iskorotkov/avro: CPU Exhaustion in DecoderCVE-2026-46384Highgithub.com/iskorotkov/avro/v2: iskorotkov/avro: Integer Overflow in Decoder

Stop the waste.
Protect your environment with Kodem.