Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-54P8-X2M9-C593Mediumgithub.com/chainguard-dev/malcontent: malcontent: Error-path cleanup gap can leak scanners and fds and degrade availabilityGHSA-5R3P-6RJ5-7937Mediumgithub.com/bytebase/bytebase: Bytebase vulnerable to Improper AuthenticationCVE-2026-28406Highgithub.com/chainguard-dev/kaniko: kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directoriesGHSA-XFX2-PRG5-JQ3GHighgithub.com/romitou/insatutorat: INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpointsCVE-2026-28407Mediumgithub.com/chainguard-dev/malcontent: malcontent: Nested archive extraction failure can drop content from scan inputsCVE-2026-28280Mediumgithub.com/jmpsec/osctrl: osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query ListCVE-2026-28279Highgithub.com/jmpsec/osctrl: osctrl is Vulnerable to OS Command Injection via Environment ConfigurationCVE-2026-28268Criticalcode.vikunja.io/api: Vikunja Vulnerable to Account Takeover via Password Reset Token ReuseCVE-2026-27945Lowgithub.com/zitadel/zitadel/v2: ZITADEL has potential SSRF via ActionsCVE-2026-27946Highgithub.com/zitadel/zitadel: ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser APICVE-2026-27840Mediumgithub.com/zitadel/zitadel: ZITADEL's truncated opaque tokens are still validCVE-2026-27734Mediumgithub.com/henrygd/beszel: Beszel: Docker API has a Path Traversal Vulnerability via Unsanitized Container IDCVE-2026-27969Criticalvitess.io/vitess: Vitess users with backup storage access can write to arbitrary file paths on restoreCVE-2026-27965Highvitess.io/vitess: Vitess users with backup storage access can gain unauthorized access to production deployment environmentsCVE-2026-22728Mediumgithub.com/bitnami-labs/sealed-secrets: Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template…GHSA-GJ6X-Q8RH-WJ6XHighgithub.com/filecoin-project/curio: Curio exposes database credentials to users with network access through verbose HTTP error responsesCVE-2026-27899Highgithub.com/h44z/wg-portal: WireGuard Portal is Vulnerable to Privilege Escalation via User Self-Update to Admin LevelCVE-2026-27896Highgithub.com/modelcontextprotocol/go-sdk: MCP Go SDK Vulnerable to Improper Handling of Case SensitivityCVE-2026-27900Mediumgithub.com/linode/terraform-provider-linode/v3: Terraform Provider for Linode Debug Logs Vulnerable to Sensitive Information ExposureCVE-2026-27465Highgithub.com/fleetdm/fleet/v4: Fleet: Sensitive Google Calendar credentials disclosed to low-privileged usersCVE-2026-25963Mediumgithub.com/fleetdm/fleet/v4: Fleet: Authorization Bypass in certificate template batch deletion for team administratorsCVE-2026-24004Mediumgithub.com/fleetdm/fleet/v4: Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint CVE-2026-23999Mediumgithub.com/fleetdm/fleet/v4: Fleet: Device lock PIN can be predicted if lock time is knownCVE-2026-27819Highcode.vikunja.io/api: Vikunja has Path Traversal in CLI RestoreCVE-2026-27808Mediumgithub.com/axllent/mailpit: Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API

Stop the waste.
Protect your environment with Kodem.