Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-23998Highgithub.com/fleetdm/fleet/v4: Fleet has a Windows MDM management endpoint authentication bypassCVE-2026-33381Mediumgithub.com/grafana/grafana: Grafana: Users can generate Service Account tokens after permissions removalCVE-2026-33380Mediumgithub.com/grafana/grafana: Grafana: SQL Expressions Read File From DiskCVE-2026-45375Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code executionCVE-2026-45371Highgithub.com/siyuan-note/siyuan/kernel: SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIsCVE-2026-45152Highgitlab.com/uniget-org/cli: uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code ExecutionCVE-2026-45148Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-modeCVE-2026-45147Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to diskGHSA-VW82-7FV8-R6GPCriticalgithub.com/obot-platform/obot: Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP serverCVE-2026-44774Mediumgithub.com/traefik/traefik/v3: Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite…CVE-2026-44740Mediumgithub.com/go-git/go-billy/v5: go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustionCVE-2026-44697Highgithub.com/klever-io/klever-go: Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payloadCVE-2026-44594Highgithub.com/esm-dev/esm.sh: esm.sh: Path Traversal via package.json browser field allows reading arbitrary server filesCVE-2026-44593Highgithub.com/esm-dev/esm.sh: esm.sh: Legacy Route Path Traversal Can Lead to RCECVE-2026-7474Highgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to a path traversalCVE-2026-6959Mediumgithub.com/hashicorp/nomad: HashiCorp Nomad vulnerable to symlink attackCVE-2026-8052Mediumgithub.com/hashicorp/nomad-driver-exec2: HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attackCVE-2026-45090Highgithub.com/hahwul/dalfox/v2: Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)CVE-2026-45089Highgithub.com/hahwul/dalfox/v2: Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` OptionCVE-2026-45088Highgithub.com/hahwul/dalfox/v2: Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`CVE-2026-45087Criticalgithub.com/hahwul/dalfox/v2: Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`CVE-2026-8349Lowgithub.com/omec-project/amf: omec-project amf crashes when processing malformed LocationReportsCVE-2026-45224Mediumgithub.com/openclaw/crabbox: Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolutionCVE-2026-45046Mediumgithub.com/safedep/gryph: Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive ContentCVE-2026-6815Mediumgithub.com/casdoor/casdoor: Casdoor: Arbitrary file write possible through Local File System storage provider

Stop the waste.
Protect your environment with Kodem.