Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44316Highgithub.com/free5gc/pcf: free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferenceCVE-2026-44315Criticalgithub.com/free5gc/nef: free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactionsCVE-2026-44309Mediumgithub.com/sigstore/gitsign: gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitsGHSA-PMWQ-PJRM-6P5RMediumgithub.com/in-toto/in-toto-golang: in-toto-golang and in-toto-python have inconsistent negation behaviorCVE-2026-44247Mediumvolcano.sh/volcano: Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body sizeCVE-2026-44588Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)GHSA-7HGR-XVRR-XPW3Lowgithub.com/nhost/nhost: nhost has Session Persistence After Password ChangeCVE-2026-44310Mediumgithub.com/sigstore/gitsign: gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callersCVE-2026-42876Mediumgithub.com/external-secrets/external-secrets/apis: ExternalSecrets vulnerable to privilege escalation with secret overwritingCVE-2026-44430Mediumgithub.com/modelcontextprotocol/registry: MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing…CVE-2026-44429Mediumgithub.com/modelcontextprotocol/registry: MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`CVE-2026-44671Highgithub.com/zitadel/zitadel: ZITADEL has LDAP Filter Injection in Login FlowCVE-2026-44428Lowgithub.com/modelcontextprotocol/registry: MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audienceCVE-2026-44427Mediumgithub.com/modelcontextprotocol/registry: MCP Registry has open redirect via protocol-relative path in trailing-slash middlewareCVE-2026-44670Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCEGHSA-FPW6-HRG5-Q5X5Highgithub.com/lin-snow/Ech0: ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTIGHSA-P64J-F4X9-WQ66Highgithub.com/lin-snow/Ech0: Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theftGHSA-8MC6-XJPR-H98XHighgithub.com/lin-snow/ech0: Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfoGHSA-PJ6Q-4VQ4-R8CGMediumgithub.com/lin-snow/Ech0: Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_countGHSA-RGJ7-VG8V-J4WRMediumgithub.com/lin-snow/ech0: Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric InflationGHSA-3V85-FQVH-7RXFMediumgithub.com/lin-snow/Ech0: Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribersGHSA-RJ4G-RQGH-RX9HMediumgithub.com/lin-snow/Ech0: Ech0 comment model's Email field returned on public /api/comments endpointsCVE-2026-44523Criticalgithub.com/enchant97/note-mark/backend: Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token ForgeryCVE-2026-44522Highgithub.com/enchant97/note-mark/backend: Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code ExecutionCVE-2026-44544Mediumgithub.com/gittuf/gittuf: gittuf's policy can be rolled back to prior valid versions

Stop the waste.
Protect your environment with Kodem.