Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45047Highgithub.com/xddxdd/bird-lg-go: Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON DecodingCVE-2026-44543Highgithub.com/rancher/local-path-provisioner: Local Path Provisioner Vulnerable to HelperPod Template InjectionCVE-2026-44477Criticalgithub.com/cloudnative-pg/cloudnative-pg: CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCECVE-2026-44474Lowgithub.com/ellanetworks/core: Ella Core has handover failures during concurrent Security Mode CommandCVE-2026-44475Mediumgithub.com/ellanetworks/core: Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequestCVE-2026-44473Highgithub.com/ellanetworks/core: Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponseCVE-2026-45022Highgithub.com/go-git/go-git/v6: go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream GitCVE-2026-44985Highgithub.com/amir20/dozzle: Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authenticationCVE-2026-42595Highgithub.com/gotenberg/gotenberg/v8: Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List BypassCVE-2026-8275Lowgithub.com/bettercap/bettercap/v2: bettercap Has an Integer Coercion Error in the ippReadChunkedBody FunctionCVE-2026-8276Lowgithub.com/bettercap/bettercap/v2: bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.goCVE-2026-44330Criticalgithub.com/free5gc/nef: free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptionsCVE-2026-44329Criticalgithub.com/free5gc/smf: free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersCVE-2026-44328Highgithub.com/free5gc/smf: free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingCVE-2026-44327Criticalgithub.com/free5gc/nef: free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerCVE-2026-44326Criticalgithub.com/free5gc/nef: free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete…CVE-2026-44325Highgithub.com/free5gc/nrf: free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible typesCVE-2026-44324Mediumgithub.com/free5gc/udr: free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)CVE-2026-44323Mediumgithub.com/free5gc/udr: free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)CVE-2026-44322Highgithub.com/free5gc/nef: free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereferenceCVE-2026-44321Highgithub.com/free5gc/smf: free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)CVE-2026-44320Highgithub.com/free5gc/nef: free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathCVE-2026-44319Highgithub.com/free5gc/nef: free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)CVE-2026-44318Mediumgithub.com/free5gc/bsf: free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on…CVE-2026-44317Mediumgithub.com/free5gc/pcf: free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference

Stop the waste.
Protect your environment with Kodem.