Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41646Mediumgithub.com/projectdiscovery/nuclei/v3: Nuclei: Local File Read via require() Module Loader BypassCVE-2026-41644Highgithub.com/monetr/monetr: monetr: Server-side request forgery in Lunch Flow link creation and refreshCVE-2026-41136Mediumgithub.com/free5gc/amf: free5GC AMF: Missing default case in Content-Type switch in HTTPUEContextTransferCVE-2026-41135Highgithub.com/free5gc/pcf: free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceCVE-2026-41131Mediumgithub.com/openfga/openfga: OpenFGA has Improper Policy EnforcementCVE-2026-32885Mediumgithub.com/ddev/ddev: DDEV has ZipSlip path traversal in tar and zip archive extractionCVE-2026-25996Mediumgithub.com/inspektor-gadget/inspektor-gadget: Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output ModeCVE-2026-24905Mediumgithub.com/inspektor-gadget/inspektor-gadget: Inspektor Gadget: Command Injection via malicious buildOptions manipulationCVE-2026-41422Highgithub.com/daptin/daptin: Daptin: SQL injection via unvalidated goqu.L() calls in aggregate APICVE-2026-41179Criticalgithub.com/rclone/rclone: RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionCVE-2026-41176Criticalgithub.com/rclone/rclone: Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionCVE-2026-41070Criticalgithub.com/jkroepke/openvpn-auth-oauth2: openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN accessCVE-2026-40938Highgithub.com/tektoncd/pipeline: Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCECVE-2026-40924Mediumgithub.com/tektoncd/pipeline: Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory ExhaustionCVE-2026-40923Mediumgithub.com/tektoncd/pipeline: Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ checkCVE-2026-40343Mediumgithub.com/free5gc/udr: free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creationCVE-2026-40161Highgithub.com/tektoncd/pipeline: Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURLCVE-2026-40264Lowgithub.com/openbao/openbao: OpenBao's Token Store Allows Cross-Namespace Renewal, RevocationCVE-2026-39946Mediumgithub.com/openbao/openbao: OpenBao's SQL Injection in PostgreSQL database secrets engineCVE-2026-39396Lowgithub.com/openbao/openbao: OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)CVE-2026-39388Lowgithub.com/openbao/openbao: OpenBao's Certificate Authentication Allows Token Renewal With Different CertificateCVE-2026-39386Highgithub.com/m1k1o/neko/server: Neko has a Self-service Privilege Escalation for Authenticated UsersCVE-2026-25542Mediumgithub.com/tektoncd/pipeline: Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matchingCVE-2026-34403Highgithub.com/0xJacky/Nginx-UI: Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpointsCVE-2026-33031Highgithub.com/0xJacky/Nginx-UI: Nginx-UI: Disabled users retain full API access through previously issued bearer tokens

Stop the waste.
Protect your environment with Kodem.