Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-8782Lowgithub.com/omec-project/amf: AMF Vulnerable to Improper Resource Shutdown or ReleaseCVE-2026-4053Lowgithub.com/mattermost/mattermost-server: Mattermost doesn't enforce the PostEditTimeLimit on non-message post fieldsCVE-2026-4054Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't validate the response body of proxied imagesGHSA-RC6V-5RMX-W5MVMediumgithub.com/arnika-project/arnika: arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLSGHSA-MXG3-432P-MR72Highgoshs.de/goshs/v2: goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP requestCVE-2026-45062Highgithub.com/dunglas/frankenphp: FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP FilesCVE-2026-8634Criticalgithub.com/openclaw/crabbox: Crabbox: environment variable exposure vulnerabilityCVE-2026-8621Highgithub.com/openclaw/crabbox: Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headersGHSA-GXHX-2686-5H9GMediumgithub.com/slack-go/slack: slack-go `SecretsVerifier` accepts empty signing secret without preconditionCVE-2026-45021Mediumgithub.com/kumahq/kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdminCVE-2026-44973Highgithub.com/go-git/go-billy/v5: go-billy has path traversal vulnerabilitiesCVE-2026-44884Mediumgithub.com/portainer/portainer: Portainer missing authorization on custom template file endpoint, which exposes template contentCVE-2026-44883Highgithub.com/portainer/portainer: Portainer: JWT accepted in URL query leaks tokens to logs and referersCVE-2026-44849Criticalgithub.com/portainer/portainer: Portainer has an endpoint security bypass via Swarm service create/updateCVE-2026-44882Highgithub.com/portainer/portainer: Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorizationCVE-2026-44881Highgithub.com/portainer/portainer: Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-UpdateCVE-2026-44850Highgithub.com/portainer/portainer: Portainer has a bind-mount restriction bypass via HostConfig.MountsCVE-2026-44885Mediumgithub.com/portainer/portainer: Portainer has a path traversal in backup archive extraction that allows arbitrary file writeCVE-2026-44848Criticalgithub.com/portainer/portainer: Portainer missing authorization on Docker plugin endpoints, which allows host RCECVE-2026-43644Mediumgithub.com/stefanprodan/podinfo: podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpointsCVE-2026-46356Mediumgithub.com/fleetdm/fleet/v4: Fleet: IP spoofing allows bypassing API rate limitingCVE-2026-26191Mediumgithub.com/fleetdm/fleet/v4: Fleet vulnerable to OS command injection in software packagesCVE-2026-26062Highgithub.com/fleetdm/fleet/v4: Fleet server may terminate unexpectedly when handling certain gRPC requestsCVE-2026-24899Highgithub.com/fleetdm/fleet/v4: Fleet Windows MDM Azure AD JWT Authentication BypassCVE-2026-24000Mediumgithub.com/fleetdm/fleet/v4: Fleet has a rate limiting bypass via untrusted client IP headers

Stop the waste.
Protect your environment with Kodem.