Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-34204Highgithub.com/minio/minio: MinIO is Vulnerable to SSE Metadata Injection via Replication HeadersCVE-2026-33433Mediumgithub.com/traefik/traefik/v2: Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldCVE-2026-32241Highgithub.com/flannel-io/flannel: Flannel has cross-node remote code execution via extension backend BackendData injectionCVE-2026-29180Mediumgithub.com/fleetdm/fleet/v4: A Fleet team maintainer can transfer hosts from any team via missing source team authorizationCVE-2026-34042Highgithub.com/nektos/act: act: actions/cache server allows malicious cache injectionCVE-2026-34041Highgithub.com/nektos/act: act: Unrestricted set-env and add-path command processing enables environment injectionCVE-2026-26061Highgithub.com/fleetdm/fleet/v4: Fleet's unbounded request body read allows remote Denial of ServiceCVE-2026-26060Mediumgithub.com/fleetdm/fleet/v4: Fleet: Password reset tokens remain valid after password change for 24 hoursCVE-2026-32695Mediumgithub.com/traefik/traefik/v3: Traefik has Knative Ingress Rule Injection that Allows Host Restriction BypassCVE-2026-34040Highgithub.com/moby/moby: Moby has AuthZ plugin bypass when provided oversized request bodiesCVE-2026-33997Mediumgithub.com/docker/docker: Moby has an Off-by-one error in its plugin privilege validationCVE-2026-33945Criticalgithub.com/lxc/incus/v6: Incus has an abitrary file write through its systemd-creds optionsCVE-2026-33898Highgithub.com/lxc/incus/v6/cmd/incus: Local Incus UI web server vulnerable to nuthentication bypassCVE-2026-33897Criticalgithub.com/lxc/incus/v6: Incus vulnerable to arbitrary file read and write through pongo templatesCVE-2026-33743Mediumgithub.com/lxc/incus/v6: Incus vulnerable to denial of source through crafted bucket backup fileCVE-2026-33711Mediumgithub.com/lxc/incus/v6: Incus vulnerable to local privilege escalation through VM screenshot pathCVE-2026-33542Highgithub.com/lxc/incus/v6/client: Incus does not verify combined fingerprint when downloading images from simplestreams serversCVE-2026-27877Mediumgithub.com/grafana/grafana: Grafana public dashboards disclose all direct mode datasourcesCVE-2026-28377Highgithub.com/grafana/tempo: Grafana Tempo has Inadequate Encryption StrengthGHSA-PRH4-VHFH-24MJMediumgithub.com/goharbor/harbor: Harbor: LDAP password and OIDC secret are not redacted in the audit logCVE-2026-33907Mediumgithub.com/ellanetworks/core: Ella Core Panics during NAS Authentication Response/Failure with missing IEsCVE-2026-33906Highgithub.com/ellanetworks/core: Ella Core has Privilege Escalation via Database Restore by NetworkManager roleCVE-2026-33904Mediumgithub.com/ellanetworks/core: Ella Core has a Denial of Service via SCTP connection cleanup deadlock CVE-2026-33903Mediumgithub.com/ellanetworks/core: Ella Core panics when processing a crafted NGAP LocationReport messageCVE-2026-21724Mediumgithub.com/grafana/grafana: Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Stop the waste.
Protect your environment with Kodem.