Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8QQM-FP2Q-V734Highgithub.com/zalando/skipper: Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policiesCVE-2026-54246Mediumgithub.com/zalando/skipper: Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack AuthenticationCVE-2026-27771Highcode.gitea.io/gitea: Gitea has insufficient permission checks for Composer package source linksGHSA-RJWR-M7QX-3FJRLowgithub.com/oapi-codegen/oapi-codegen/v2: oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable CodeCVE-2026-54247Mediumgithub.com/zalando/skipper: Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoSCVE-2026-52724Mediumgithub.com/kumahq/kuma/v2: kuma-dp connects to control plane without verifying TLS certificate when no CA is configuredCVE-2026-52832Mediumgithub.com/nuclio/nuclio: Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containerCVE-2026-52833Highgithub.com/nuclio/nuclio: Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCECVE-2026-53714Highgithub.com/envoyproxy/gateway: Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode CVE-2026-53713Criticalgithub.com/envoyproxy/gateway: Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret DisclosureCVE-2026-53715Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lockCVE-2026-53717Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar headerCVE-2026-53719Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationCVE-2026-53716Mediumgithub.com/envoyproxy/gateway: Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limitCVE-2026-53718Mediumgithub.com/envoyproxy/gateway: Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypassCVE-2026-50166Mediumgithub.com/kumahq/kuma/v2: kumactl connects to control plane without verifying TLS certificate when no CA is configuredCVE-2026-58196Lowgithub.com/stacklok/toolhive: ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)CVE-2026-50285Highgithub.com/pomerium/pomerium: Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE CallbackCVE-2026-50274Highgithub.com/DataDog/dd-trace-go: dd-trace-go: Improper parsing of W3C baggage headers may lead to DoSCVE-2026-54495Mediumgithub.com/open-feature/open-feature-operator: open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant…CVE-2026-54452Mediumgithub.com/doyensec/safeurl: safeurl is Missing IPv6 CIDR Ranges in BlocklistCVE-2026-54450Lowgithub.com/stacklok/toolhive: ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gatewayCVE-2026-61549Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backendGHSA-7RX3-5WX3-5V76Highgithub.com/forgekeep/nebula-mesh: Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`CVE-2026-61699Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Certificate revocation is never enforced at the mesh

Stop the waste.
Protect your environment with Kodem.