Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45627Highgithub.com/getarcaneapp/arcane/backend: Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeoverCVE-2026-45626Mediumgithub.com/getarcaneapp/arcane/backend: Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameterCVE-2026-45625Criticalgithub.com/getarcaneapp/arcane/backend: Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and…CVE-2026-45135Highgithub.com/caddyserver/caddy/v2: Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP FilesGHSA-MX64-MJ3Q-7PRJHighgithub.com/iskorotkov/avro/v2: iskorotkov/avro: Denial-of-Service Vulnerability in DecoderCVE-2026-6347Highgithub.com/mattermost/mattermost-server: Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin CVE-2026-5163Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't verify channel membership when processing AI-assisted message rewritesCVE-2026-6343Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't check public/private permissionsCVE-2026-6339Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpointCVE-2026-6333Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate the Host header when constructing response URLs for custom slash commandCVE-2026-6345Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't prevent disclosure of created user passwordCVE-2026-6346Highgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generationCVE-2026-28732Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't enforce slash command trigger-word uniqueness during command updatesCVE-2026-4286Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't check if {{team_id}} was being changed when updating playbooksCVE-2026-4273Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmationCVE-2026-6340Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate 7zip archive structure before processingCVE-2026-6334Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flowCVE-2026-28759Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost does not verify remote cluster channel access when processing shared channel membership removalsCVE-2026-2325Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't limit the size of the request body on the start meeting API endpointCVE-2026-3495Lowgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't escape some variables that could contain malicious content during error page compositionCVE-2026-3637Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't check the create_post channel permission during post edit operationsCVE-2026-8783Lowgithub.com/omec-project/amf: AMF Vulnerable to Improper Resource Shutdown or ReleaseCVE-2026-8780Lowgithub.com/omec-project/amf: AMF Improperly Restricts Operations within the Bounds of a Memory BufferCVE-2026-8779Lowgithub.com/omec-project/amf: AMF Improperly Restricts Operations within the Bounds of a Memory BufferCVE-2026-8781Lowgithub.com/omec-project/amf: AMF Vulnerable to Improper Resource Shutdown or Release

Stop the waste.
Protect your environment with Kodem.