Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26186Mediumgithub.com/fleetdm/fleet/v4: Fleet has an SQL Injection vulnerability via backtick escape in ORDER BY parameterCVE-2026-27730Highgithub.com/esm-dev/esm.sh: esm.sh has SSRF localhost/private-network bypass in `/http(s)` module routeCVE-2026-27616Highcode.vikunja.io/api: Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token ExposureCVE-2026-27575Criticalcode.vikunja.io/api: Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password ChangeCVE-2026-27116Mediumcode.vikunja.io/api: Vikunja has Reflected HTML Injection via filter Parameter in its Projects ModuleCVE-2026-1229Lowgithub.com/cloudflare/circl: CIRCL has an incorrect calculation in secp384r1 CombinedMultCVE-2026-24005Lowgithub.com/openkruise/kruise: OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host FieldGHSA-2PHG-QGMM-R638Highgithub.com/BishopFox/sliver: Sliver has Potential Zip Bomb Denial of Service in GzipEncoderCVE-2026-27626Criticalgithub.com/OliveTin/OliveTin: OliveTin: OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checksCVE-2026-27611Highgithub.com/gtsteffaniak/filebrowser/backend: FileBrowser Quantum: Password Protection Not Enforced on Shared File Links CVE-2025-50180Highgithub.com/esm-dev/esm.sh: esm.sh is vulnerable to full-response SSRFCVE-2026-27598Highgithub.com/dagu-org/dagu: Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directoryCVE-2026-25882Mediumgithub.com/gofiber/fiber/v2: Fiber has a Denial of Service Vulnerability via Route Parameter OverflowCVE-2026-25899Highgithub.com/gofiber/fiber/v3: Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded AllocationCVE-2026-25891Highgithub.com/gofiber/fiber/v3: Fiber has an Arbitrary File Read in Static Middleware on WindowsCVE-2026-27590Highgithub.com/caddyserver/caddy/v2: Caddy: Unicode case-folding length expansion causes incorrect split_path index in FastCGI transportCVE-2026-27589Mediumgithub.com/caddyserver/caddy/v2: Caddy is vulnerable to cross-origin config application via local admin API /load CVE-2026-27588Highgithub.com/caddyserver/caddy/v2: Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypassCVE-2026-27587Highgithub.com/caddyserver/caddy/v2: Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypassCVE-2026-27586Highgithub.com/caddyserver/caddy/v2: Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformedCVE-2026-27585Mediumgithub.com/caddyserver/caddy/v2: Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protectionsCVE-2026-27571Mediumgithub.com/nats-io/nats-server/v2: nats-server websockets are vulnerable to pre-auth memory DoSCVE-2026-25802Highgithub.com/QuantumNous/new-api: New API has Potential XSS in its MarkdownRenderer componentCVE-2026-25591Highgithub.com/QuantumNous/new-api: New API has an SQL LIKE Wildcard Injection DoS via Token SearchGHSA-GV8R-9RW9-9697Highgithub.com/traefik/traefik: Traefik affected by TLS ClientAuth Bypass on HTTP/3

Stop the waste.
Protect your environment with Kodem.