Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-VJGJ-42F6-7997Mediumgithub.com/tinfoil-factory/netfoil: netfoil's optional seccomp sandboxing was not appliedGHSA-84G5-X8J3-7235Mediumgithub.com/tinfoil-factory/netfoil: Netfoil has incorrect allowlist enforcementCVE-2026-44015Highgithub.com/0xJacky/Nginx-UI: Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal ServicesCVE-2026-41643Highgithub.com/osrg/gobgp/v4: GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATECVE-2026-41642Highgithub.com/osrg/gobgp/v4: GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path AttributeCVE-2026-33467Mediumgithub.com/elastic/package-registry: Elastic Package Registry has Improper Verification of Cryptographic Signature CVE-2026-35579Highgithub.com/coredns/coredns: CoreDNS has TSIG authentication bypass on gRPC and QUIC transportsCVE-2026-33190Highgithub.com/coredns/coredns: CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPCCVE-2026-33489Highgithub.com/coredns/coredns: CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)CVE-2026-32936Highgithub.com/coredns/coredns: CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplificationCVE-2026-32934Highgithub.com/coredns/coredns: CoreDNS' DoQ worker pool does not bound stream backlogCVE-2026-30246Mediumgithub.com/gofiber/fiber/v3: Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parametersCVE-2026-38651Criticalgithub.com/gravitl/netmaker: Netmaker does not verify JWT signatures for host tokensCVE-2026-41602Highgithub.com/apache/thrift: Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerabilityCVE-2026-7020Lowgithub.com/ollama/ollama: Ollama is Vulnerable to Path TraversalCVE-2026-41572Mediumgithub.com/enchant97/note-mark/backend: Note Mark: Unauthenticated read of notes and assets in soft-deleted public booksCVE-2026-41571Criticalgithub.com/enchant97/note-mark/backend: Note Mark: OIDC-registered users authenticated by submitting password "null"CVE-2026-41520Highgithub.com/cilium/cilium: Cillium exposes sensitive information included in the cilium-bugtool debug archiveCVE-2026-42275Highgithub.com/openziti/zrok: zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/writeCVE-2026-42274Highgithub.com/dadrus/heimdall: Heimdall has an authorization bypass via path normalization mismatchCVE-2026-42273Highgithub.com/dadrus/heimdall: Heimdall: Case-sensitive host matching may lead to policy bypassCVE-2026-42272Highgithub.com/dadrus/heimdall: Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretationCVE-2026-6993Mediumgithub.com/go-kratos/kratos/v2: Kratos has a Confused Deputy issueCVE-2026-6987Mediumgithub.com/sipeed/picoclaw: PicoClaw has an Injection issue in its Web Launcher Management Plane componentGHSA-H829-5CG7-6HFFMediumgithub.com/supply-chain-tools/gitverify: gitverify has improper tag signature verification

Stop the waste.
Protect your environment with Kodem.