Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-25773Highgithub.com/mattermost/focalboard: Focalboard doesn't sanitize category IDs before incorporating them into dynamic SQL statementsCVE-2026-28736Mediumgithub.com/mattermost/focalboard: Focalboard doesn't validate file ownership when serving uploaded filesCVE-2026-5467Lowgithub.com/casdoor/casdoor: Casdoor vulnerable to Open RedirectCVE-2026-35393Criticalgithub.com/patrickhener/goshs: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart uploadCVE-2026-35392Criticalgithub.com/patrickhener/goshs: goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT UploadCVE-2026-34992Highantrea.io/antrea: Antrea has Missing Encryption of Sensitive DataCVE-2026-35037Highgithub.com/lin-snow/ech0: Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadataCVE-2026-35036Highgithub.com/lin-snow/ech0: Ech0 has Unauthenticated Server-Side Request Forgery in Website Preview FeatureCVE-2026-34986Highgithub.com/go-jose/go-jose/v4: Go JOSE Panics in JWE decryptionCVE-2026-34976Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing AuthorizationCVE-2026-4370Criticalgithub.com/juju/juju: Juju has Improper TLS Client/Server authentication and certificate verification on Database ClusterCVE-2026-34828Highgithub.com/knadh/listmonk: listmonk's active sessions remain valid after password reset and password changeCVE-2026-34783Highgithub.com/MontFerret/ferret/v2: Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websitesCVE-2026-34969Lowgithub.com/nhost/nhost: Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider CallbackCVE-2026-34940Highgithub.com/kubeai-project/kubeai: KubeAI: OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model podsGHSA-PRXJ-3GCV-CQRHMediumgithub.com/teslamotors/fleet-telemetry: Tesla Fleet Telemetry allows spoofing telemetry for arbitrary vehicles via compromised vehicle credentialsCVE-2026-34762Lowgithub.com/ellanetworks/core: Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriberCVE-2026-34761Mediumgithub.com/ellanetworks/core: Ella Core Panics Upon NGAP handover failureCVE-2026-34742Highgithub.com/modelcontextprotocol/go-sdk: DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on LocalhostGHSA-RXMP-8H9V-56CXMediumgithub.com/netbirdio/netbird: NetBird has Race Condition on UpdateUser Function, Resulting in Privilege Escalation From Admin to OwnerCVE-2026-34581Highgithub.com/patrickhener/goshs: goshs has Auth Bypass via Share TokenCVE-2026-33544Highgithub.com/steveiliop56/tinyauth: Tinyauth has OAuth account confusion via shared mutable state on singleton service instancesCVE-2026-5199Lowgo.temporal.io/server: Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same…CVE-2026-34605Highgithub.com/siyuan-note/siyuan/kernel: SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)CVE-2026-34585Highgithub.com/siyuan-note/siyuan/kernel: SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution

Stop the waste.
Protect your environment with Kodem.