Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-35469Highgithub.com/moby/spdystream: SpdyStream: DOS on CRICVE-2026-6383Mediumkubevirt.io/kubevirt: KubeVirt's authorization mechanism improperly truncates subresource namesCVE-2026-21726Mediumgithub.com/grafana/loki/v3: Grafana Loki Path Traversal - CVE-2021-36156 BypassCVE-2025-41118Criticalgithub.com/grafana/pyroscope: Pyroscope Exposes Storage SecretCVE-2026-41059Highgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regexCVE-2026-40574Mediumgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email ClaimsCVE-2026-40575Criticalgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header SpoofingCVE-2026-6290Criticalwww.velocidex.com/golang/velociraptor: Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL tokenCVE-2024-53412Highgithub.com/NietThijmen/ShoppingCart: NietThijmen ShoppingCart: Command injection in the connect functionCVE-2026-41145Highgithub.com/minio/minio: MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer UploadsGHSA-HW5X-4R37-72W7Lowgithub.com/opentofu/opentofu: OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responsesCVE-2026-40910Mediumgithub.com/fatedier/frp: frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access controlCVE-2026-40944Highgithub.com/oxia-db/oxia: Oxia's TLS CA certificate chain validation fails with multi-certificate PEM bundlesCVE-2026-40943Highgithub.com/oxia-db/oxia: Oxia affected by server crash via race condition in session heartbeat handlingCVE-2026-40946Criticalgithub.com/oxia-db/oxia: Oxia has an OIDC token audience validation bypass via SkipClientIDCheckCVE-2026-40945Highgithub.com/oxia-db/oxia: Oxia exposes bearer token in debug log messages on authentication failureCVE-2026-40922Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has incomplete fix for CVE-2026-33066: XSSGHSA-7QX6-F23W-3W7FLowgithub.com/patrickhener/goshs: Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect`…CVE-2026-40890Highgithub.com/gomarkdown/markdown: Go Markdown has an Out-of-bounds Read in SmartypantsRendererCVE-2026-4789Highgithub.com/kyverno/kyverno: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data accessCVE-2026-40091Mediumgithub.com/authzed/spicedb: SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logsCVE-2026-40090Highgithub.com/zarf-dev/zarf: Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File WriteCVE-2026-34457Criticalgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2 Proxy's Health Check User-Agent Matching Bypasses Authentication in auth_request ModeCVE-2026-34454Lowgithub.com/oauth2-proxy/oauth2-proxy/v7: OAuth2 Proxy's session cookies are not cleared when rendering sign-in pageCVE-2026-33414Mediumgithub.com/containers/podman/v4: PowerShell Command Injection in Podman HyperV Machine

Stop the waste.
Protect your environment with Kodem.