Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55622Highgithub.com/lxc/incus/v7/cmd/incusd: Incus has a project restriction bypass in instance copy across projectsCVE-2026-55621Highgithub.com/lxc/incus/v7: Incus has a project restriction bypass for custom volume copy across projectsCVE-2026-55245Highgithub.com/maximhq/bifrost/core: Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURLCVE-2026-55588Loworas.land/oras: ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource ConsumptionCVE-2026-55068Criticalgithub.com/free5gc/free5gc: free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsCVE-2026-55067Mediumcode.vikunja.io/api: Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignmentCVE-2026-55066Highcode.vikunja.io/api: Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_idCVE-2026-55065Highcode.vikunja.io/api: Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled KeyCVE-2026-55064Mediumcode.vikunja.io/api: Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0CVE-2026-54766Mediumcode.vikunja.io/api: Vikunja has a project duplication bypasses write-permission check on the target parent projectCVE-2026-55834Mediumgithub.com/pocket-id/pocket-id/backend: Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=noneCVE-2026-55569Mediumgithub.com/aquaproj/aqua/v2: Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directoryCVE-2026-54755Criticalgithub.com/klever-io/klever-go: Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)CVE-2026-54754Criticalgithub.com/klever-io/klever-go: Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)CVE-2026-55108Highgithub.com/oam-dev/kubevela: KubeVela Terraform remote loader DoS via unbounded file readCVE-2026-54746Mediumgithub.com/hatchet-dev/hatchet: Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and UnsubscribeGHSA-MF7Q-R4RV-JV94Highgithub.com/crossplane/crossplane-runtime/v2: Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…CVE-2026-42350Lowgithub.com/akuity/kargo: Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query ParameterCVE-2026-54563Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account rootCVE-2026-54523Criticalgithub.com/kyverno/kyverno: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any…CVE-2026-55637Highgithub.com/geiserx/genieacs-mcp: genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transportCVE-2026-55092Highgithub.com/aquasecurity/trivy: Trivy has a path traversal via a crafted vulnerability database or other downloaded artifactsCVE-2026-55677Highgithub.com/labstack/echo/v5: Echo: Encoded slash (%2F) bypasses route-level protection and exposes static filesCVE-2026-55580Highgithub.com/sonirico/mcp-shell: mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode AllowlistCVE-2026-55581Highgithub.com/sonirico/mcp-shell: mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

Stop the waste.
Protect your environment with Kodem.