Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-35599Mediumcode.vikunja.io/api: Vikunja has Algorithmic Complexity DoS in Repeating Task HandlerCVE-2026-35598Mediumcode.vikunja.io/api: Vikunja Missing Authorization on CalDAV Task ReadCVE-2026-35597Mediumcode.vikunja.io/api: Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account LockoutCVE-2026-35596Mediumcode.vikunja.io/api: Vikunja has Broken Access Control on Label Read via SQL Operator Precedence BugCVE-2026-35595Highcode.vikunja.io/api: Vikunja vulnerable to Privilege Escalation via Project ReparentingCVE-2026-35206Mediumhelm.sh/helm/v4: Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segmentCVE-2026-35205Highhelm.sh/helm/v4: Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin installCVE-2026-35204Highhelm.sh/helm/v4: Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directoryCVE-2026-35594Mediumcode.vikunja.io/api: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgradeCVE-2026-34727Highcode.vikunja.io/api: Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login PathCVE-2026-39414Highgithub.com/minio/minio: MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV ParsingCVE-2026-4660Highgithub.com/hashicorp/go-getter: HashiCorp's go-getter library may allow arbitrary file readsCVE-2026-21388Lowgithub.com/mattermost/mattermost-plugin-msteams: Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint CVE-2026-24661Mediumgithub.com/mattermost/mattermost-plugin-msteams: Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpointCVE-2026-40293Mediumgithub.com/openfga/openfga: OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML responseCVE-2026-39972Highgithub.com/dunglas/mercure: mercure has Topic Selector Cache Key CollisionCVE-2026-39901Mediumgithub.com/monetr/monetr: monetr: Protected Transactions Deletable via PUTCVE-2026-39883Highgo.opentelemetry.io/otel/sdk: opentelemetry-go: BSD kenv command not using absolute path enables PATH hijackingCVE-2026-39882Mediumgo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodiesCVE-2026-27806Highgithub.com/fleetdm/fleet/v4: Fleet Affected by Local Privilege Escalation via Tcl Command Injection in OrbitGHSA-H9MW-H4QC-F5JFMediumgithub.com/platform-mesh/kubernetes-graphql-gateway: kubernetes-graphql-gateway: GraphQL Endpoint Vulnerable to Authenticated Denial-of-Service via Unrestricted Query ExecutionCVE-2026-39429Highgithub.com/kcp-dev/kcp: kcp's cache server is accessible without authentication or authorization checksCVE-2026-39846Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsGHSA-XMRV-PMRH-HHX2Mediumgithub.com/aws/aws-sdk-go-v2/aws/protocol/eventstream: Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream DecoderCVE-2026-39395Mediumgithub.com/sigstore/cosign: Cosign's verify-blob-attestation reports false positive when payload parsing fails

Stop the waste.
Protect your environment with Kodem.