Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-34530Mediumgithub.com/filebrowser/filebrowser/v2: File Browser vulnerable to Stored Cross-site Scripting via text/template branding injectionCVE-2026-34528Highgithub.com/filebrowser/filebrowser/v2: File Browser's Signup Grants Execution Permissions When Default Permissions Includes ExecutionCVE-2026-34529Highgithub.com/filebrowser/filebrowser/v2: File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB fileCVE-2026-34453Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmarkCVE-2026-34449Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet InjectionCVE-2026-34448Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop ClientCVE-2026-34227Mediumgithub.com/bishopfox/sliver: Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP InterfaceCVE-2026-25726Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)CVE-2026-34389Mediumgithub.com/fleetdm/fleet/v4: Fleet's user account creation via invite does not enforce invited email addressCVE-2026-34388Mediumgithub.com/fleetdm/fleet/v4: Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpointCVE-2026-34386Mediumgithub.com/fleetdm/fleet/v4: Fleet vulnerable to SQL Injection in MDM bootstrap package by authenticated team or global adminCVE-2026-34385Mediumgithub.com/fleetdm/fleet/v4: Fleet's Apple MDM profile delivery has second-order SQL Injection that can compromise the databaseCVE-2026-34165Mediumgithub.com/go-git/go-git/v5: go-git: Maliciously crafted idx file can cause asymmetric memory consumptionCVE-2026-33990Mediumgithub.com/docker/model-runner: Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)CVE-2026-33762Lowgithub.com/go-git/go-git/v5: go-git missing validation decoding Index v4 files leads to panicCVE-2026-33032Criticalgithub.com/0xJacky/Nginx-UI: nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx TakeoverCVE-2026-33030Highgithub.com/0xJacky/nginx-ui: nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private KeysCVE-2026-33029Mediumgithub.com/0xJacky/Nginx-UI: nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate IntervalCVE-2026-33028Highgithub.com/0xJacky/Nginx-UI: nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service CollapseCVE-2026-33027Mediumgithub.com/0xJacky/Nginx-UI: Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path ValidationCVE-2026-33026Criticalgithub.com/0xJacky/Nginx-UI: nginx-ui Backup Restore Allows Tampering with Encrypted BackupsCVE-2026-27018Highgithub.com/gotenberg/gotenberg/v8: Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)GHSA-46WH-3698-F2CXHighgithub.com/traefik/traefik/v2: Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)GHSA-C279-989M-238FHighgithub.com/bishopfox/sliver: Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attemptedCVE-2026-32287Highgithub.com/antchfx/xpath: XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion

Stop the waste.
Protect your environment with Kodem.