Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-HWQM-QVJ9-4JR2Highgithub.com/russellhaering/gosaml2: gosaml2 CBC Padding Panic — Unauthenticated Process CrashCVE-2026-33487Highgithub.com/russellhaering/goxmldsig: validateSignature Loop Variable Capture Signature Bypass in goxmldsigGHSA-VCCX-P757-PV6HLowgithub.com/k1LoW/mo: mo has a XSS via inline SVG script tags in Markdown renderingCVE-2026-33192Highgithub.com/free5gc/udm: free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions requesCVE-2026-33191Highgithub.com/free5gc/udm: free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server ErrorCVE-2026-33203Highgithub.com/siyuan-note/siyuan/kernel: SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive BypassCVE-2026-33194Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home (GHSA-h5vh-m7fg-w5h6 Bypass)CVE-2026-33186Criticalgoogle.golang.org/grpc: gRPC-Go has an authorization bypass via missing leading slash in :pathCVE-2026-33065Mediumgithub.com/free5gc/udm: free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions requestCVE-2026-33064Highgithub.com/free5gc/udm: free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer DereferenceCVE-2026-33063Highgithub.com/free5gc/ausf: free5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface ConversionCVE-2026-33062Highgithub.com/free5gc/nrf: free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list ParameterCVE-2026-32937Highgithub.com/free5gc/chf: Out-of-Bounds Slice Access in free5GC CHF Leading to DoSCVE-2026-33132Mediumgithub.com/zitadel/zitadel: Zitadel is missing enforcement of organization scopesCVE-2026-33081Mediumgithub.com/pinchtab/pinchtab: PinchTab has a Blind SSRF via browser-side redirect bypass in /download URL validationCVE-2026-33067Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package MetadataCVE-2026-33066Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan has Stored XSS to RCE via Unsanitized Bazaar README RenderingCVE-2026-32811Highgithub.com/dadrus/heimdall: Heimdall: Path received via Envoy gRPC corrupted when containing query stringCVE-2026-32286Highgithub.com/jackc/pgproto3/v2: Denial of service in github.com/jackc/pgproto3/v2CVE-2026-32285Highgithub.com/buger/jsonparser: github.com/buger/jsonparser has a denial of service vulnerabilityCVE-2026-32284Highgithub.com/shamaton/msgpack/v2: Denial of service in github.com/shamaton/msgpackCVE-2026-32761Mediumhttps://github.com/filebrowser/filebrowser: File Browser has an Authorization Policy Bypass in Public Share Download FlowGHSA-594F-3595-C47VMediumgithub.com/argoproj-labs/terraform-provider-argocd: Terraform Provider for ArgoCD has possible exposure to GO-2026-4337 / CVE-2025-68121CVE-2026-33022Mediumgithub.com/tektoncd/pipeline: Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRunCVE-2026-32953Mediumgithub.com/tillitis/tkeyclient: Tillitis TKey Client has an Error in Protocol Implementation

Stop the waste.
Protect your environment with Kodem.