Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-G9WW-X58F-9G6MHighgithub.com/edgelesssys/contrast: Contrast BadAML injection allows arbitrary code executionCVE-2026-33758Criticalgithub.com/openbao/openbao: OpenBao has Reflected XSS in its OIDC authentication error messageCVE-2026-33757Criticalgithub.com/openbao/openbao: OpenBao lacks user confirmation for OIDC direct callback modeCVE-2026-3112Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configurationCVE-2026-3114Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't validate decompressed archive entry sizes during file extractionCVE-2026-3108Highgithub.com/mattermost/mattermost/server/v8: Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequencesCVE-2026-3113Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't set permissions on downloaded bulk exportCVE-2026-3115Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scopeCVE-2026-33748Highgithub.com/moby/buildkit: BuildKit Git URL subdir component can cause access to restricted filesCVE-2026-33747Highgithub.com/moby/buildkit: BuildKit's Malicious frontend can cause file escape outside of storage rootCVE-2026-33729Mediumgithub.com/openfga/openfga: OpenFGA has an Authorization Bypass through cached keysGHSA-2PV8-4C52-MF8JCriticalcode.vikunja.io/api: Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDORCVE-2026-33726Mediumgithub.com/cilium/cilium: Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node trafficCVE-2026-4274Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost has an Incorrect Authorization issueCVE-2026-33809Mediumgolang.org/x/image: Go Images vulnerable to an out-of-memory error via a crafted TIFF fileCVE-2026-33700Mediumcode.vikunja.io/api: Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share DeletionCVE-2026-33680Highcode.vikunja.io/api: Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission EscalationCVE-2026-33679Mediumcode.vikunja.io/api: Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download CVE-2026-33678Highcode.vikunja.io/api: Vikjuna: IDOR in Task Attachment ReadOne Allows Cross-Project File Access and DeletionCVE-2026-33677Mediumcode.vikunja.io/api: Vikjuna: Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via APICVE-2026-33676Mediumcode.vikunja.io/api: Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task ReadCVE-2026-33675Mediumcode.vikunja.io/api: Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network ResourcesCVE-2026-33668Highcode.vikunja.io/api: Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID ConnectCVE-2026-33529Lowgithub.com/tobychui/zoraxy: Zoraxy: Authenticated Path Traversal in Config Import leads to RCECVE-2026-33670Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan has directory traversal within its publishing service

Stop the waste.
Protect your environment with Kodem.