Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41485Highgithub.com/kyverno/kyverno: Kyverno Controller Denial of Service via forEach Mutation PanicCVE-2026-41263Mediumgithub.com/traefik/traefik/v3: Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middlewareCVE-2026-41174Mediumgithub.com/traefik/traefik/v3: Traefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingCVE-2026-40912Highgithub.com/traefik/traefik/v3: Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath DesyncGHSA-RP7V-4384-HFRPHighgithub.com/k8sgpt-ai/k8sgpt: k8sGPT has Prompt Injection through its k8sGPT-OperatorCVE-2026-39858Highgithub.com/traefik/traefik/v3: Traefik: Pre-authentication decision bypass due to forwarded alias spoofingCVE-2026-35051Highgithub.com/traefik/traefik/v3: Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authenticationGHSA-XHJ4-G6W8-2XJWCriticalgithub.com/woven-planet/go-zserio: go-zserio has Unbounded Memory Allocation for All PlatformsCVE-2026-41492Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/varsCVE-2026-41432Highgithub.com/QuantumNous/new-api: New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota FraudCVE-2026-41328Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang FieldCVE-2026-41327Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition FieldCVE-2026-41246Highgithub.com/projectcontour/contour: Contour has Lua code injection via Cookie Path Rewrite PolicyCVE-2026-21728Highgithub.com/grafana/tempo: Grafana Tempo has an Uncontrolled Resource Consumption issueCVE-2026-29051Lowchainguard.dev/melange: melange has Path Traversal via .PKGINFO in --persist-lint-resultsCVE-2026-29050Mediumchainguard.dev/melange: melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].usesCVE-2026-40886Highgithub.com/argoproj/argo-workflows/v4: Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows ControllerCVE-2026-32952Mediumgithub.com/Azure/go-ntlmssp: go-ntlmssp NTLM challenges can panic on malformed payloadsCVE-2026-39087Criticalheckel.io/ntfy/v2: ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions functionCVE-2026-42091Mediumgithub.com/patrickhener/goshs/v2: goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORSCVE-2026-42072Criticalgithub.com/orneryd/nornicdb: NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote accessCVE-2026-41894Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869)CVE-2026-41889Lowgithub.com/jackc/pgx/v5: pgx: SQL Injection via placeholder confusion with dollar quoted string literalsGHSA-3M6Q-H5GJ-7MRWMediumcode.gitea.io/gitea: Gitea has insecure default SSH settingsCVE-2026-41645Mediumgithub.com/projectdiscovery/nuclei/v3: Nuclei: Environment variable disclosure via Response-Derived DSL Expressions

Stop the waste.
Protect your environment with Kodem.