Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24692Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly enforce read permissions in search API endpointsCVE-2026-4265Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to validate team-specific upload_file permissionsCVE-2026-21386Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to use consistent error responses when handling the /mute commandCVE-2026-2456Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to limit the size of responses from integration action endpointsCVE-2026-2461Mediumgithub.com/mattermost/mattermost-plugin-boards: Mattermost Boards Plugin fails to implement authorisation checks on comment block modificationsCVE-2026-2476Highgithub.com/mattermost/mattermost-plugin-msteams: Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration valuesCVE-2026-2458Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows a removed team member to enumerate all public channels within a private teamCVE-2026-2463Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to filter invite IDs based on user permissionsCVE-2026-2578Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to preserve the redacted state of burn-on-read posts during deletionCVE-2026-2457Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost allows attackers to spoof permalink embedsCVE-2026-26246Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to bound memory allocation when processing PSD image filesCVE-2026-25783Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate User-Agent header tokensCVE-2026-24458Highgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly handle very long passwordsCVE-2026-25780Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to bound memory allocation when processing DOC filesCVE-2026-32720Highgithub.com/ctfer-io/monitoring: github.com/ctfer-io/monitoring Vulnerable to Improper Access ControlCVE-2026-32704Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DBGHSA-Q926-C743-49QJLowgithub.com/centrifugal/centrifugo/v6: Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warningCVE-2026-32301Criticalgithub.com/centrifugal/centrifugo/v6: Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URLCVE-2026-30961Mediumgithub.com/forceu/gokapi: Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk UploadCVE-2026-30955Mediumgithub.com/forceu/gokapi: Gokapi vulnerable to DoS in E2E Metadata ParserCVE-2026-30943Mediumgithub.com/forceu/gokapi: Gokapi vulnerable to Privilege Escalation in File ReplaceCVE-2026-30915Mediumgithub.com/drakkan/sftpgo/v2: SFTPGo improperly sanitizes placeholders in group home directories/key prefixesCVE-2026-30914Mediumgithub.com/drakkan/sftpgo/v2: SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization DiscrepancyCVE-2026-32614Criticalgithub.com/emmansun/gmsm: SM9 Infinity-Point Ciphertext Forgery VulnerabilityCVE-2026-31886Criticalgithub.com/dagu-org/dagu: Dagu: Path Traversal via `dagRunId` in Inline DAG Execution

Stop the waste.
Protect your environment with Kodem.