Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-42297Highgithub.com/argoproj/argo-workflows/v4: Argo has Missing Authorization in its Sync ConfigMap ProviderCVE-2026-41685Mediumgithub.com/lxc/incus/v6/cmd/incusd: Incus is affected by unbounded binary import disk exhaustionCVE-2026-41684Mediumgithub.com/lxc/incus/v6/cmd/incusd: Incus has Nil Dereferences on Restore via Malformed YAMLCVE-2026-41648Mediumgithub.com/lxc/incus/v6/cmd/incusd: Incus has Unbounded YAML Metadata Decode via ParsingCVE-2026-41647Mediumgithub.com/lxc/incus/v6/cmd/incusd: Incus has Nil-Pointer Dereference via S3 Bucket ImportCVE-2026-41326Highgithub.com/kata-containers/kata-containers: Kata Container has CopyFile Policy Subversion via SymlinksCVE-2026-41181Mediumgithub.com/traefik/traefik/v2: Traefik's errors middleware forwards Authorization and Cookie headers to separate error page serviceCVE-2026-40893Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and MoveCVE-2026-40251Highgithub.com/lxc/incus/v6/cmd/incusd: Incus Vulnerable to Panic via Snapshot Bounds CheckCVE-2026-40243Lowgithub.com/lxc/incus/v6/cmd/incusd: Incus has an OVN TLS Verification that Accepts Peer-Supplied RootsCVE-2026-37461Highgithub.com/osrg/gobgp/v4: GoBGP has an out-of-bounds read in the ParseIP6Extended functionCVE-2026-40197Highgithub.com/lxc/incus/v6/cmd/incusd: Incus has a Nil-Pointer Dereference via Custom Volume ImportCVE-2026-40195Highgithub.com/lxc/incus/v6/cmd/incusd: Incus has a Nil-Pointer Dereference Panic via Bucket MetadataCVE-2026-35527Mediumgithub.com/lxc/incus/v6/cmd/incusd: Incus has Blind SSRF via Image Import Preflight HEADCVE-2026-7482Highgithub.com/ollama/ollama: Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loaderCVE-2026-7736Mediumgithub.com/osrg/gobgp/v4: GoBGP has an Integer Underflow IssueCVE-2026-7737Mediumgithub.com/osrg/gobgp: GoBGP has Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2026-7734Mediumgithub.com/osrg/gobgp/v4: GoBGP has an Improper Resource Shutdown or ReleaseGHSA-RH99-WC69-C255Highgithub.com/edgelesssys/contrast: Contras Affected by CopyFile Policy Subversion via SymlinksCVE-2026-42461Highgithub.com/getarcaneapp/arcane/backend: Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) CVE-2026-42560Criticalgithub.com/go-pkgz/auth: auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonationGHSA-28XX-PPPM-VQFFLowgithub.com/ydb-platform/ydb-go-sdk/v3: ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transactionCVE-2026-40281Criticalgithub.com/gotenberg/gotenberg/v8: Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)CVE-2026-39383Mediumgithub.com/gotenberg/gotenberg/v8: Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URLCVE-2026-40280Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Stop the waste.
Protect your environment with Kodem.