Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-FCMH-QFXC-W685Mediumgithub.com/cloudnativelabs/kube-router/v2: kube-router: BGP Peer Passwords Exposed in Logs at Verbose Logging LevelCVE-2026-35607Highgithub.com/filebrowser/filebrowser/v2: File Browser: Proxy auth auto-provisioned users inherit Execute permission and CommandsCVE-2026-35606Mediumgithub.com/filebrowser/filebrowser/v2: File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download checkCVE-2026-35604Highgithub.com/filebrowser/filebrowser/v2: File Browser share links remain accessible after Share/Download permissions are revokedCVE-2026-35605Mediumgithub.com/filebrowser/filebrowser/v2: File Browser has an access rule bypass via HasPrefix without trailing separator in path matchingCVE-2026-35585Highgithub.com/filebrowser/filebrowser/v2: File Browser has a Command Injection via Hook RunnerCVE-2026-29181Highgo.opentelemetry.io/otel: OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)CVE-2026-33815Criticalgithub.com/jackc/pgx/v5: pgx contains memory-safety vulnerabilityCVE-2026-33816Criticalgithub.com/jackc/pgx/v5: Memory-safety vulnerability in github.com/jackc/pgx/v5.GHSA-QMWH-9M9C-H36MHighgithub.com/gotenberg/gotenberg/v8: Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tagsCVE-2026-35458Highgithub.com/gotenberg/gotenberg/v8: Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope featureCVE-2026-34972Mediumgithub.com/openfga/openfga: OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collisionCVE-2026-4740Highopen-cluster-management.io/ocm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validationCVE-2026-35480Mediumgithub.com/ipld/go-ipld-prime: go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headersGHSA-X3F4-V83F-7WP2Highgithub.com/authorizerdev/authorizer: Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uriGHSA-JFWG-RXF3-P7R9Highgithub.com/authorizerdev/authorizer: Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String InterpolationCVE-2026-35172Highgithub.com/distribution/distribution/v3: Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidationCVE-2026-33540Highgithub.com/distribution/distribution/v3: Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realmCVE-2026-35454Highgithub.com/coder/code-marketplace: Code Extension Marketplace: Zip Slip Path TraversalCVE-2026-35166Mediumgithub.com/gohugoio/hugo: Hugo: Certain markdown links are not properly escapedCVE-2026-35471Criticalgithub.com/patrickhener/goshs: goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)CVE-2025-68153Highgithub.com/juju/juju: Juju has a resource poisoning vulnerabilityCVE-2025-68152Mediumgithub.com/juju/juju: Juju: Read All Controller Logs From Compromised WorkloadCVE-2026-5469Mediumgithub.com/casdoor/casdoor: Casdoor vulnerable to SSRF via crafted Webhook URLCVE-2026-5468Lowgithub.com/casdoor/casdoor: Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml

Stop the waste.
Protect your environment with Kodem.