Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-73232Highgithub.com/ffuf/ffuf/v2: ffuf denial of service (OOM) via HTTP response decompression bombCVE-2026-61625Mediumgithub.com/VictoriaMetrics/VictoriaMetrics: VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore rootCVE-2026-75602Mediumgithub.com/OpenListTeam/OpenList: OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolCVE-2026-56743Mediumgithub.com/cilium/cilium: Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock matchGHSA-GW25-M53R-QH88Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)GHSA-99RQ-75J6-5J9FHighgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypassCVE-2026-73667Highgithub.com/openchoreo/openchoreo: OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged podsCVE-2026-73840Mediumgithub.com/openchoreo/openchoreo: OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)CVE-2026-73841Highgithub.com/openchoreo/openchoreo: OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpointsCVE-2026-73843Criticalgithub.com/openchoreo/openchoreo: OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsCVE-2026-67445Highgithub.com/axllent/mailpit: Mailpit: SMTP command parser buffers unbounded command lines before syntax rejectionCVE-2026-72921Highgithub.com/seaweedfs/seaweedfs: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsCVE-2026-67446Highgithub.com/axllent/mailpit: Mailpit: Thumbnail generation decodes unbounded image dimensions before scalingCVE-2026-72920Criticalgithub.com/seaweedfs/seaweedfs: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlCVE-2026-59832Highgithub.com/siyuan-note/siyuan/kernel: Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.dbCVE-2026-59834Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: SQL Query in Block Search Exposes Hidden Published Document ContentCVE-2026-84304Highgoogle.golang.org/grpc: gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationCVE-2026-55785Lowgithub.com/free5gc/ausf: free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKACVE-2026-55784Highgithub.com/free5gc/ausf: free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPICVE-2026-55874Highgithub.com/seaweedfs/seaweedfs: SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readCVE-2026-55873Mediumgithub.com/seaweedfs/seaweedfs: SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned…CVE-2026-55764Highgithub.com/klever-io/klever-go: klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupplyCVE-2026-55678Mediumgithub.com/basekick-labs/arc: arc has unauthenticated cluster node admission when `cluster.shared_secret` is unsetCVE-2026-55761Highgithub.com/portainer/portainer: Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized InstancesCVE-2026-55763Highgithub.com/klever-io/klever-go: klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

Stop the waste.
Protect your environment with Kodem.