Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33669Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan has Arbitrary Document Reading within the Publishing ServiceCVE-2026-27656Mediumgithub.com/mattermost/mattermost-server: Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flawCVE-2026-27659Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost doesn't properly validate CSRF tokensCVE-2026-26233Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't rate limit login requests, allowing DoSCVE-2026-20719Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds CVE-2026-27889Highgithub.com/nats-io/nats-server/v2: NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsReadCVE-2026-33638Mediumgithub.com/lin-snow/ech0: Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint CVE-2026-33248Mediumgithub.com/nats-io/nats-server/v2: NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingCVE-2026-33246Mediumgithub.com/nats-io/nats-server/v2: NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headersCVE-2026-33223Mediumgithub.com/nats-io/nats-server/v2: NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity SpoofingCVE-2026-33222Mediumgithub.com/nats-io/nats-server/v2: NATS JetStream has an authorization bypass through its Management APICVE-2026-33219Mediumgithub.com/nats-io/nats-server/v2: NATS is vulnerable to pre-auth DoS through WebSockets client serviceCVE-2026-33218Highgithub.com/nats-io/nats-server/v2: NATS has pre-auth server panic via leafnode handlingCVE-2026-33217Highgithub.com/nats-io/nats-server/v2: NATS allows MQTT clients to bypass ACL checksCVE-2026-33216Highgithub.com/nats-io/nats-server/v2: NATS has MQTT plaintext password disclosureCVE-2026-33215Mediumgithub.com/nats-io/nats-server/v2: NATS is vulnerable to MQTT hijacking via Client IDCVE-2026-29785Highgithub.com/nats-io/nats-server/v2: NATS Server panic via malicious compression on leafnode portCVE-2026-33247Highgithub.com/nats-io/nats-server/v2: NATS credentials are exposed in monitoring port via command-line argvCVE-2026-33249Mediumgithub.com/nats-io/nats-server/v2: NATS: Message tracing can be redirected to arbitrary subjectCVE-2026-33621Mediumgithub.com/pinchtab/pinchtab: PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API TokenCVE-2026-33623Mediumgithub.com/pinchtab/pinchtab/cmd/pinchtab: PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command ExecutionCVE-2026-33622Mediumgithub.com/pinchtab/pinchtab/cmd/pinchtab: A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript ExecutionCVE-2026-33620Mediumgithub.com/pinchtab/pinchtab: PinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and Intermediary SystemsCVE-2026-33619Mediumgithub.com/pinchtab/pinchtab: PinchTab has Unauthenticated Blind SSRF in Task Scheduler via Unvalidated callbackUrlCVE-2026-54685Mediumgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

Stop the waste.
Protect your environment with Kodem.