Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26311Mediumgithub.com/envoyproxy/envoy: Envoy: HTTP - filter chain execution on reset streams causing UAF crashCVE-2026-26309Mediumgithub.com/envoyproxy/envoy: Envoy affected by off-by-one write in JsonEscaper::escapeString()CVE-2026-26308Highgithub.com/envoyproxy/envoy: Envoy has RBAC Header Validation Bypass via Multi-Value Header ConcatenationCVE-2026-26310Mediumgithub.com/envoyproxy/envoy: Envoy vulnerable to crash for scoped ip address during DNSGHSA-XV8G-FJ9H-6GMVCriticalgithub.com/shi-gg/linkdave: Linkdave Missing Authentication on REST and WebSocket endpointsCVE-2026-30934Highgithub.com/gtsteffaniak/filebrowser: FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)CVE-2026-30933Highgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum: Password-Protected Share Bypass via /public/api/share/infoCVE-2026-30926Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildrenCVE-2026-29773Mediumgithub.com/kubewarden/kubewarden-controller: Kubewarden: Cross-namespace data exfiltration via deprecated host callback bindingCVE-2026-29196Highgithub.com/gravitl/netmaker: Netmaker: Service User with Network Access Can Access config files with WireGuard Private KeysCVE-2026-29195Mediumgithub.com/gravitl/netmaker: Netmaker has Privilege Escalation from Admin to Super-Admin via User UpdateCVE-2026-29194Highgithub.com/gravitl/netmaker: Netmaker has Insufficient Authorization in Host Token VerificationCVE-2026-28513Highgithub.com/pocket-id/pocket-id/backend: Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchangeCVE-2026-28512Highgithub.com/pocket-id/pocket-id/backend: Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusionGHSA-QR2G-P6Q7-W82MHigh@x402/svm: x402 SDK Security AdvisoryCVE-2026-30869Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret LeakageCVE-2026-30861Criticalgithub.com/Tencent/WeKnora: WeKnora has Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration ValidationCVE-2026-30860Criticalgithub.com/Tencent/WeKnora: WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query ToolCVE-2026-30859Highgithub.com/Tencent/WeKnora: WeKnora has Broken Access Control - Cross-Tenant Data ExposureCVE-2026-30858Highgithub.com/Tencent/WeKnora: WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal ResourcesCVE-2026-30857Mediumgithub.com/Tencent/WeKnora: WeKnora has Unauthorized Cross‑Tenant Knowledge Base CloningCVE-2026-30856Mediumgithub.com/Tencent/WeKnora: WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt InjectionCVE-2026-30855Criticalgithub.com/Tencent/WeKnora: WeKnora Vulnerable to Broken Access Control in Tenant ManagementCVE-2026-30852Mediumgithub.com/caddyserver/caddy/v2/modules/caddyhttp: Caddy's vars_regexp double-expands user input, leaking env vars and filesCVE-2026-30851Highgithub.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy: Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation

Stop the waste.
Protect your environment with Kodem.