Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44425Mediumgithub.com/shellhub-io/shellhub: ShellHub has crash-DoS via field injection in filter and sort-by parametersCVE-2026-44423Mediumgithub.com/shellhub-io/shellhub: ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session dataCVE-2026-44424Mediumgithub.com/shellhub-io/shellhub: ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespaceGHSA-MHC4-QQ83-FMRRMediumgithub.com/getaxonflow/axonflow-sdk-go/v5: axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verificationGHSA-9H64-2846-7X7FCriticalgithub.com/getaxonflow/axonflow: Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardeningGHSA-2CCX-CJJH-R2J8Lowgithub.com/bluenviron/mediamtx: MediaMTX affected by CVE-2026-27143 due to vulnerable dependencyCVE-2026-42602Highgithub.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension: opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayCVE-2026-44245Mediumgithub.com/kyverno/policy-reporter-ui: Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard ComponentCVE-2026-44349Highgithub.com/daptin/daptin: Daptin fuzzy search injects unvalidated column name into raw SQLCVE-2026-42572Mediumgithub.com/hatchet-dev/hatchet: Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`GHSA-V5MH-H5HX-7V92Mediumgithub.com/cloudnativelabs/kube-router: kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route InjectionCVE-2026-44301Mediumgithub.com/gohugoio/hugo: Hugo's Node tool execution allows file system access outside the project directoryCVE-2025-71261Highgithub.com/harvester/harvester: Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSGHSA-6447-269V-G68MHighgithub.com/mezo-org/mezod: Mezo: ERC-20 bridgeOut burn can be erased by a stale StateDB overwrite leading to full L1 bridge drainCVE-2026-6863Mediumwww.velocidex.com/golang/velociraptor: Velocidex Velociraptor has an Incorrect Authorization issueCVE-2026-42339Highgithub.com/QuantumNous/new-api: QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0CVE-2026-42283Highgithub.com/loft-sh/devspace: DevSpace UI Server WebSocket CheckOrigin does not validate sourceCVE-2026-42238Criticalgithub.com/0xJacky/nginx-ui: Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup RestoreCVE-2026-42223Mediumgithub.com/0xJacky/nginx-ui: Nginx-UI Settings API Exposes Protected SecretsCVE-2026-42222Highgithub.com/0xJacky/nginx-ui: Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeoverCVE-2026-42221Highgithub.com/0xJacky/Nginx-UI: Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin ClaimCVE-2026-7573Mediumwww.velocidex.com/golang/velociraptor: Velocidex Velociraptor has an authorization bypass vulnerabilityCVE-2026-7572Mediumwww.velocidex.com/golang/velociraptor: Velocidex Velociraptor has an off-by-one errorCVE-2026-6970Highgithub.com/canonical/authd: authd: Primary group ID is incorrectly set to value of UID CVE-2026-44903Mediumgithub.com/prometheus/prometheus: Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

Stop the waste.
Protect your environment with Kodem.