Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-33312Mediumcode.vikunja.io/api: Vikunja read-only users can delete project background images via broken object-level authorizationCVE-2026-32595Mediumgithub.com/traefik/traefik: Traefik Affected by BasicAuth Middleware Timing Attack Allows Username EnumerationCVE-2026-32305Highgithub.com/traefik/traefik/v3: Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS ConfigCVE-2026-29794Mediumcode.vikunja.io/api: Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed HeadersCVE-2026-4342Highk8s.io/ingress-nginx: ingress-nginx comment-based nginx configuration injectionCVE-2026-33353Highgithub.com/charmbracelet/soft-serve: In Soft Serve, an authenticated repo import can clone server-local private repositoriesCVE-2026-33344Highgithub.com/dagu-org/dagu: Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAGCVE-2026-26933Mediumgithub.com/elastic/beats/v7: Packetbeat does not properly validate an array index in multiple protocol parser componentsCVE-2026-26931Mediumgithub.com/elastic/beats/v7: Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of ServiceCVE-2026-33322Criticalgithub.com/minio/minio: MinIO has JWT Algorithm Confusion in OIDC AuthenticationCVE-2026-33283Mediumgithub.com/ellanetworks/core: Ella Core panics on malformed ULNASTransport Message without a Request TypeCVE-2026-33282Highgithub.com/ellanetworks/core: Ella Core panics on malformed NGAP Location ReportCVE-2026-33281Mediumgithub.com/ellanetworks/core: Ella Core panics on invalid PDU Session IDs in NGAP messagesCVE-2026-32694Mediumgithub.com/juju/juju: Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju SecretsCVE-2026-32693Highgithub.com/juju/juju: Juju has unauthorized access to out-of-scope Kubernetes secretsCVE-2026-32692Highgithub.com/juju/juju: Juju has unauthorized update of out-of-scope Vault secretsCVE-2026-33252Highgithub.com/modelcontextprotocol/go-sdk: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdkCVE-2026-30924Criticalgithub.com/autobrr/qui: qui CORS Misconfiguration: Arbitrary Origins TrustedCVE-2026-30836Criticalgithub.com/smallstep/certificates: step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)CVE-2026-33320Mediumgithub.com/tomwright/dasel/v3: Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of serviceGHSA-Q382-VC8Q-7JHJHighgithub.com/modelcontextprotocol/go-sdk: Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdkCVE-2026-32691Mediumgithub.com/juju/juju: Juju affected by timing ownership claim attack on new external back-end secretsCVE-2026-33221Lowgithub.com/nhost/nhost: Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage UploadCVE-2026-33211Criticalgithub.com/tektoncd/pipeline: Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver podGHSA-PCGW-QCV5-H8CHHighgithub.com/russellhaering/gosaml2: Unsigned SAML LogoutRequest Acceptance in gosaml2

Stop the waste.
Protect your environment with Kodem.