Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-MMPX-JH39-WRV6Mediumgithub.com/gtsteffaniak/filebrowser: FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)CVE-2026-44542Criticalgithub.com/gtsteffaniak/filebrowser: FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File DeletionCVE-2026-44283Lowgo.etcd.io/etcd/v3: etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requestsCVE-2026-44426Mediumgithub.com/shellhub-io/shellhub: ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership checkGHSA-258C-965C-P3HCMediumgithub.com/daptin/daptin: Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password ChangeGHSA-M38G-VWW2-MVGXHighgithub.com/siderolabs/talos: Talos Linux has a local privilege escalation from untrusted workloadsCVE-2026-44514Mediumgithub.com/kubetail-org/kubetail/modules/dashboard: Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated usersCVE-2026-42459Highgithub.com/free5gc/udm: Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive InformationCVE-2026-42328Mediumgithub.com/ipld/go-ipld-prime: go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depthCVE-2026-42083Highgithub.com/free5gc/pcf: Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPICVE-2026-42880Criticalgithub.com/argoproj/argo-cd/v3: ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionCVE-2026-42082Lowgithub.com/free5gc/amf: Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover CVE-2026-42081Mediumgithub.com/free5gc/amf: Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequestCVE-2026-44503Highcom.microsoft.kiota:microsoft-kiota-abstractions: Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirectCVE-2026-41050Criticalgithub.com/rancher/fleet: Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template renderingCVE-2026-25705Highgithub.com/rancher/rancher: Rancher Extensions have arbitrary file access via path traversalGHSA-FC67-C4HG-Q653Highgithub.com/aws/amazon-ecs-agent: Amazon ECS Container Agent (Windows) is vulnerable to Information DisclosureCVE-2026-42597Mediumgithub.com/gotenberg/gotenberg/v8: Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// schemeCVE-2026-42596Criticalgithub.com/gotenberg/gotenberg/v8: Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhookCVE-2026-42594Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutineCVE-2026-42593Mediumgithub.com/gotenberg/gotenberg/v8: Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesCVE-2026-42592Mediumgithub.com/gotenberg/gotenberg/v8: Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routesCVE-2026-42591Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has a Server-Side Request Forgery (SSRF) IssueCVE-2026-42590Highgithub.com/gotenberg/gotenberg/v8: Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklistCVE-2026-42589Criticalgithub.com/gotenberg/gotenberg/v8: Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection

Stop the waste.
Protect your environment with Kodem.