Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32941Mediumgithub.com/bishopfox/sliver: Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard TransportsCVE-2026-32254Highgithub.com/cloudnativelabs/kube-router/v2: Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoSCVE-2026-32940Criticalgithub.com/siyuan-note/siyuan: SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)CVE-2026-32938Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan Vulnerable to Arbitrary File Read in Desktop Publish ServiceCVE-2026-26304Mediumgithub.com/mattermost/mattermost-plugin-playbooks: Mattermost fails to verify run_create permission for empty playbookIdCVE-2026-32828Mediumgithub.com/akuity/kargo: Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data ExfiltrationCVE-2026-32769Highgithub.com/ctfer-io/fullchain: Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespaceCVE-2026-32805Highgithub.com/ctfer-io/romeo/webserver: Romeo is vulnerable to Archive Slip due to missing checks in sanitizationCVE-2026-32771Highgithub.com/ctfer-io/monitoring: Monitoring is vulnerable to Archive Slip due to missing checks in sanitizationCVE-2026-32737Highgithub.com/ctfer-io/romeo/environment/deploy: Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace CVE-2026-32768Highgithub.com/ctfer-io/chall-manager/deploy: Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespaceCVE-2026-32758Mediumgithub.com/filebrowser/filebrowser/v2: File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination ParameterCVE-2026-32767Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search APICVE-2026-32760Criticalgithub.com/filebrowser/filebrowser/v2: File Browser Signup Grants Admin When Default Permissions Include AdminGHSA-V3MG-9V85-FCM7Mediumsiyuan: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSSCVE-2026-32759Mediumgithub.com/filebrowser/filebrowser/v2: File Browser TUS Negative Upload-Length Fires Post-Upload Hooks PrematurelyCVE-2026-32751Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile InterfaceCVE-2026-32750Mediumgithub.com/siyuan-note/siyuan: SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notesCVE-2026-32749Highgithub.com/siyuan-note/siyuan/kernel: SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file writeCVE-2026-32815Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information DisclosureCVE-2026-32747Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secretsCVE-2026-30405Highgithub.com/osrg/gobgp/v4: GoBGP vulnerable to a denial of service via the NEXT_HOP path attributeCVE-2026-32606Highgithub.com/lxc/incus-os/incus-osd: IncusOS has a LUKS encryption bypass due to insufficient TPM policyCVE-2026-22545Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to validate user's authentication method when processing account auth type switchCVE-2026-2455Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation

Stop the waste.
Protect your environment with Kodem.