Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33634Criticalgithub.com/aquasecurity/trivy: Trivy ecosystem supply chain was briefly compromisedCVE-2026-33528Mediumgithub.com/yusing/godoxy: GoDoxy has a Path Traversal Vulnerability in its File APICVE-2026-33525Lowgithub.com/authelia/authelia/v4: Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site ScriptingCVE-2026-30886Mediumgithub.com/QuantumNous/new-api: New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check CVE-2026-32879Mediumgithub.com/QuantumNous/new-api: New API has passkey-based secure step-up verification bypass for root-only channel secret disclosureCVE-2026-24516Highgithub.com/digitalocean/droplet-agent: DigitalOcean Droplet Agent: Command Injection via Metadata Service EndpointCVE-2026-4404Criticalgithub.com/goharbor/harbor: Harbor allows the use of the default password for web UI loginCVE-2026-4531Mediumgithub.com/free5gc/amf: Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete functionCVE-2026-3864Mediumgithub.com/kubernetes-csi/csi-driver-nfs: NFS CSI driver for Kubernetes is Vulnerable to Path Traversal through Volume Identifier ParameterCVE-2026-33505Highgithub.com/ory/keto: Ory Keto has a SQL injection via forged pagination tokensCVE-2026-33504Highgithub.com/ory/hydra: Ory Hydra has a SQL injection via forged pagination tokensCVE-2026-33503Highgithub.com/ory/kratos: Ory Kratos has a SQL injection via forged pagination tokensCVE-2026-33494Criticalgithub.com/ory/oathkeeper: Ory Oathkeeper has a path traversal authorization bypassCVE-2026-33496Highgithub.com/ory/oathkeeper: Ory Oathkeeper has an authentication bypass by cache key confusionCVE-2026-33495Mediumgithub.com/ory/oathkeeper: Ory Oathkeeper has an authentication bypass by usage of untrusted headerCVE-2026-33413Highgo.etcd.io/etcd/v3: etcd: Authorization bypasses in multiple APIsCVE-2026-33419Criticalgithub.com/minio/minio: MinIO LDAP login brute-force via user enumeration and missing rate limitCVE-2026-33481Mediumgithub.com/anchore/syft: Syft improper temporary file cleanupCVE-2026-33476Highgithub.com/siyuan-note/siyuan/kernel: Siyuan has an Unauthenticated Arbitrary File Read via Path TraversalCVE-2026-33474Mediumcode.vikunja.io/api: Vikunja Affected by DoS via Image Preview GenerationCVE-2026-33473Mediumcode.vikunja.io/api: Vikunja has TOTP Reuse During Validity WindowCVE-2026-33343Lowgo.etcd.io/etcd/v3: etcd: Nested etcd transactions bypass RBAC authorization checksCVE-2026-33316Highcode.vikunja.io/api: Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement CVE-2026-33315Mediumcode.vikunja.io/api: Vikunja has a 2FA Bypass via Caldav Basic AuthCVE-2026-33313Mediumcode.vikunja.io/api: Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments

Stop the waste.
Protect your environment with Kodem.