Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40885Highgithub.com/patrickhener/goshs/v2: goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized accessCVE-2026-40883Mediumgithub.com/patrickhener/goshs/v2: goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creationCVE-2026-40884Criticalgithub.com/patrickhener/goshs: goshs has an empty-username SFTP password authentication bypassCVE-2026-40876Highgithub.com/patrickhener/goshs: SFTP root escape via prefix-based path validation in goshsCVE-2026-40868Highgithub.com/kyverno/kyverno: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount tokenGHSA-FMQP-4WFC-W3V7Highgithub.com/kyverno/kyverno: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation BreachGHSA-QR4G-8HRP-C4RWHighgithub.com/kyverno/kyverno: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRFCVE-2026-40249Mediumgithub.com/free5gc/udr: free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errorsCVE-2026-40248Highgithub.com/free5gc/udr: free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsCVE-2026-40247Highgithub.com/free5gc/udr: free5gc UDR improper path validation allows unauthenticated access to Traffic Influence SubscriptionsCVE-2026-40246Highgithub.com/free5gc/udr: free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence SubscriptionsCVE-2026-40245Highgithub.com/free5gc/udr: free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationCVE-2026-39984Mediumgithub.com/sigstore/timestamp-authority/v2: Sigstore Timestamp Authority has Improper Certificate Validation in verifierCVE-2026-40344Highgithub.com/minio/minio: MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer UploadsCVE-2026-40481Highgithub.com/monetr/monetr: In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validationCVE-2026-40265Mediumgithub.com/enchant97/note-mark/backend: Note Mark has Broken Access Control on Asset DownloadCVE-2026-40263Lowgithub.com/enchant97/note-mark/backend: Note Mark: Username Enumeration via Login Endpoint Timing Side-ChannelCVE-2026-40262Highgithub.com/enchant97/note-mark/backend: Note Mark has Stored XSS via Unrestricted Asset UploadCVE-2026-40193Highgithub.com/foxcpp/maddy: Maddy Mail Server has an LDAP Filter Injection via Unsanitized UsernameCVE-2026-40179Mediumgithub.com/prometheus/prometheus: Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorerCVE-2026-34984Highgithub.com/external-secrets/external-secrets: External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engineCVE-2026-34476Highgithub.com/apache/skywalking-mcp: Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP ServerGHSA-9CP7-J3F8-P5JXCriticalgithub.com/daptin/daptin: Daptin has Unauthenticated Path Traversal and Zip SlipCVE-2026-5724Mediumgo.temporal.io/server: Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpointCVE-2026-5774Mediumgithub.com/juju/juju: Juju: In-Memory Token Store for Discharge Tokens Lacks Concurrency Safety and Persistence

Stop the waste.
Protect your environment with Kodem.