Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-42541Mediumgithub.com/kubewarden/kubewarden-controller: Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability callCVE-2026-44166Mediumgithub.com/pocketbase/pocketbase: PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgradeGHSA-9FW6-XGG2-MQ9QHighgithub.com/apernet/hysteria/core/v2: Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabledCVE-2026-42300Criticalgithub.com/l3montree-dev/devguard: DevGuard has an unauthenticated identity assertion via `X-Admin-Token` headerCVE-2026-42285Highgithub.com/osrg/gobgp/v4: GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)CVE-2026-42220Mediumgithub.com/0xJacky/Nginx-UI: Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and…CVE-2026-42554Mediumgithub.com/gofiber/fiber/v3: Fiber vulnerable to XSS in AutoFormat Content NegotiationCVE-2026-42600Mediumgithub.com/minio/minio: MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST EndpointCVE-2026-42186Lowgithub.com/openbao/openbao: OpenBao's Namespace Deletion May Not Delete Data ProperlyCVE-2026-42154Highgithub.com/prometheus/prometheus: Prometheus: Remote read endpoint allows denial of service via crafted snappy payloadCVE-2026-42151Highgithub.com/prometheus/prometheus: Prometheus Azure AD remote write OAuth client secret exposed via config APICVE-2026-42882Criticalgithub.com/oxyno-zeta/s3-proxy: S3-Proxy has Security Issues in its Resource Path Matching ImplementationCVE-2026-42875Mediumgithub.com/external-secrets/external-secrets: External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStoreGHSA-H5FQ-653G-GXRMMediumgithub.com/Luzifer/ots: ots has a negative expire override that can bypass its secret retention policyCVE-2026-41164Mediumgithub.com/nuts-foundation/nuts-node: nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access tokenCVE-2026-7776Highgithub.com/hashicorp/boundary: Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakesCVE-2026-42575Highchainguard.dev/apko: apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)CVE-2026-42574Highchainguard.dev/apko: apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build rootCVE-2026-42576Mediumchainguard.dev/apko: apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discoveryCVE-2026-42571Criticalgithub.com/pelicanplatform/pelican: Pelican Web UI Affected by a Privilege Escalation AttackCVE-2026-41888Mediumgithub.com/distribution/distribution/v3: Distribution's tag deletion bypasses `storage.delete.enabled` configurationCVE-2026-42295Highgithub.com/argoproj/argo-workflows/v4: Argo vulnerable to exposure of artifact repository credentialsCVE-2026-42296Highgithub.com/argoproj/argo-workflows/v3: Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/SecureCVE-2026-42294Highgithub.com/argoproj/argo-workflows/v3: Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook InterceptorCVE-2026-42183Lowgithub.com/argoproj/argo-workflows/v4: Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Stop the waste.
Protect your environment with Kodem.