Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-30832Criticalgithub.com/charmbracelet/soft-serve: soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo importCVE-2026-29064Highgithub.com/zarf-dev/zarf/src/pkg/archive: Zarf's symlink targets in archives are not validated against destination directoryCVE-2026-26018Highgithub.com/coredns/coredns: CoreDNS Loop Detection Denial of Service VulnerabilityCVE-2026-30834Highgithub.com/pinchtab/pinchtab/cmd/pinchtab: PinchTab has SSRF with Full Response Exfiltration via Download HandlerCVE-2026-26017Highgithub.com/coredns/coredns: CoreDNS ACL BypassCVE-2026-30247Mediumgithub.com/Tencent/WeKnora: WeKnora is Vulnerable to SSRF via RedirectionCVE-2026-30233Mediumgithub.com/OliveTin/OliveTin: OliveTin doesn't check view permission when returning dashboardsGHSA-FWHJ-785H-43HHMediumgithub.com/OliveTin/OliveTin: OliveTin has crash on NPE by calling APIs with invalid bindings or log referencesCVE-2026-30225Mediumgithub.com/OliveTin/OliveTin: OliveTin's RestartAction always runs actions as guestCVE-2026-30224Mediumgithub.com/OliveTin/OliveTin: OliveTin Session Fixation: Logout Fails to Invalidate Server-Side SessionCVE-2026-30223Highgithub.com/OliveTin/OliveTin: OliveTin has JWT Audience Validation Bypass in Local Key and HMAC ModesCVE-2026-29084Mediumgithub.com/forceu/gokapi: Gokapi has CSRF in Login EndpointCVE-2026-29061Mediumgithub.com/forceu/gokapi: Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotionCVE-2026-26276Highgogs.io/gogs: Gogs: DOM-based XSS via milestone selectionCVE-2026-26196Mediumgogs.io/gogs: Gogs: Access tokens get exposed through URL params in API requestsCVE-2026-26195Mediumgogs.io/gogs: Gogs: Stored XSS in branch and wiki views through author and committer namesCVE-2026-26194Highgogs.io/gogs: Gogs: Release tag option injection in release deletionCVE-2026-26022Highgogs.io/gogs: Gogs: Stored XSS via data URI in issue commentsCVE-2026-25921Criticalgogs.io/gogs: Gogs: Cross-repository LFS object overwrite via missing content hash verificationCVE-2026-29060Mediumgithub.com/forceu/gokapi: Gokapi has privilege escalation with auth tokenCVE-2026-28683Highgithub.com/forceu/gokapi: Gokapi has Stored XSS in SVG HotlinksCVE-2026-28682Mediumgithub.com/forceu/gokapi: Gokapi has Data Leak in Upload Status StreamCVE-2026-27944Criticalgithub.com/0xJacky/Nginx-UI: Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key DisclosureCVE-2026-29791Mediumgithub.com/agentgateway/agentgateway: Agentgateway is missing parameter sanitization in MCP to OpenAPI conversionCVE-2026-29781Lowgithub.com/bishopfox/sliver: Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers

Stop the waste.
Protect your environment with Kodem.