Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-15558Highgithub.com/docker/cli: Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on WindowsCVE-2026-29192Highgithub.com/zitadel/zitadel/v2: ZITADEL: Stored XSS via Default URI Redirect Leads to Account TakeoverCVE-2026-29193Highgithub.com/zitadel/zitadel/v2: ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and AuthenticationCVE-2026-29191Criticalgithub.com/zitadel/zitadel: ZITADEL has 1-Click Account Takeover via XSS in /saml-post EndpointCVE-2026-29188Criticalgithub.com/filebrowser/filebrowser/v2: File Browser's TUS Delete Endpoint Bypasses Delete Permission CheckCVE-2026-29771Highgithub.com/gravitl/netmaker: Netmaker Vulnerable to Denial of Service via Server Shutdown EndpointCVE-2026-29183Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon EndpointCVE-2026-29054Highgithub.com/traefik/traefik/v2: traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example,…CVE-2026-29042Highgithub.com/nuclio/nuclio: Nuclio Shell Runtime Command Injection Leading to Privilege EscalationCVE-2026-3351Mediumgithub.com/canonical/lxd: lxd's non-recursive certificate listing bypasses per-object authorization and leaks all fingerprintsCVE-2026-26999Highgithub.com/traefik/traefik/v2: Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)CVE-2026-26998Mediumgithub.com/traefik/traefik/v2: Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOSCVE-2026-29073Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan's direct SQL Query API accessible to Reader-level users enables unauthorized database accessCVE-2025-62879Mediumgithub.com/rancher/backup-restore-operator: Rancher Backup Operator pod's logs leak S3 tokensCVE-2021-25320Criticalgithub.com/rancher/rancher: Rancher cloud credentials can be used through proxy API by users without accessGHSA-HWM2-4PH6-W6M5Highgithub.com/rancher/rancher: Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged userCVE-2022-21951Mediumgithub.com/rancher/rancher: Rancher's weave CNI password is not configured when a cluster is created from an RKE templateCVE-2022-31247Criticalgithub.com/rancher/rancher: Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)CVE-2021-36783Criticalgithub.com/rancher/rancher: Rancher doesn't properly sanitize credentials in cluster template answersCVE-2023-22648Highgithub.com/rancher/rancher: Rancher's Azure AD permission changes are not reflected on active sessionsCVE-2026-29049Mediumchainguard.dev/melange: `melange update-cache` has unbounded HTTP download that can exhaust disk in CICVE-2026-28790Highgithub.com/OliveTin/OliveTin: OliveTin has Unauthenticated Action Termination via KillAction When Guests Must LoginCVE-2026-28789Highgithub.com/OliveTin/OliveTin: OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handlingCVE-2026-28492Highgithub.com/filebrowser/filebrowser/v2: FileBrowser has Path Traversal in Public Share Links that Exposes Files Outside Shared DirectoryCVE-2026-28342Highgithub.com/OliveTin/OliveTin: OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint

Stop the waste.
Protect your environment with Kodem.