Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-72798Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columnsCVE-2026-72799Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readersCVE-2026-72800Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration…CVE-2026-72801Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline…CVE-2026-72802Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPathCVE-2026-72803Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields)…CVE-2026-72804Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documentsCVE-2026-72805Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of…CVE-2026-72806Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents…CVE-2026-72807Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on…CVE-2026-72808Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)CVE-2026-72809Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxyCVE-2026-72810Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including…CVE-2026-72811Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and…CVE-2026-72812Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated…CVE-2026-68584Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)CVE-2026-68585Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden…CVE-2026-68586Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of…CVE-2026-68587Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable…CVE-2026-69083Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method…CVE-2026-69086Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view…CVE-2026-69084Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle,…CVE-2026-79921Highgithub.com/rabbitmq/amqp091-go: amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized PayloadCVE-2026-73293Highgithub.com/semaphoreui/semaphore: Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collisionCVE-2026-73292Highgithub.com/semaphoreui/semaphore: Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

Stop the waste.
Protect your environment with Kodem.