Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-6634Lowgithub.com/usememos/memos: Memos has an Incorrect Privilege Assignment issueCVE-2026-41589Criticalcharm.land/wish/v2: Wish has SCP Path Traversal that allows arbitrary file read/writeCVE-2026-6437Mediumgithub.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fieldsCVE-2026-41574Criticalgithub.com/nhost/nhost: Nhost Vulnerable to Account Takeover via OAuth Email Verification BypassCVE-2026-41506Mediumgithub.com/go-git/go-git/v5: go-git: Credential leak via cross-host redirect in smart HTTP transportCVE-2026-41433Highgo.opentelemetry.io/obi: OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIRCVE-2026-41491Highgithub.com/dapr/dapr: Dapr: Service Invocation path traversal ACL bypassCVE-2026-3590Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcementCVE-2026-27769Lowgithub.com/mattermost/mattermost-server: Mattermost doesn't validate whether users were correctly owned by the correct Connected WorkspaceCVE-2026-5160Mediumgithub.com/yuin/goldmark/renderer/html: goldmark vulnerable to Cross-site Scripting (XSS)CVE-2026-28741Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate CSRF tokens on an authentication endpointCVE-2026-5807Highgithub.com/hashicorp/vault: HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey OperationsCVE-2026-5052Mediumgithub.com/hashicorp/vault: HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNSCVE-2026-3605Highgithub.com/hashicorp/vault: HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-ServiceCVE-2026-4525Highgithub.com/hashicorp/vault: HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header SanitizationCVE-2026-41413Mediumistio.io/istio: Istio: SSRF via RequestAuthentication jwksUriGHSA-8WFP-579W-6R25Highgithub.com/kyverno/kyverno: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)CVE-2026-41323Highgithub.com/kyverno/kyverno: Kyverno: ServiceAccount token leaked to external servers via apiCall service URLCVE-2026-41068Highgithub.com/kyverno/kyverno: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)CVE-2026-40611Highgithub.com/go-acme/lego/v4: ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 ProviderCVE-2026-40304Mediumgithub.com/openziti/zrok: zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend recordsCVE-2026-40303Highgithub.com/openziti/zrok: zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsingCVE-2026-40302Mediumgithub.com/openziti/zrok: zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error renderingCVE-2026-40173Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpointsCVE-2026-39350Mediumistio.io/istio: Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots

Stop the waste.
Protect your environment with Kodem.