Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24122Lowgithub.com/sigstore/cosign: Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skippedGHSA-J9WF-6R2X-HQMXMediumgithub.com/centrifugal/centrifugo/v6: Centrifugo v6.6.0 dependency vulnerabilitiesGHSA-6QR9-G2XW-CW92Criticalgithub.com/dagu-org/dagu: Dagu affected by unauthenticated RCE via inline DAG spec in default configurationCVE-2026-26963Mediumgithub.com/cilium/cilium: Cilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabledCVE-2026-24834Mediumgithub.com/kata-containers/kata-containers/src/runtime: Kata Container to Guest micro VM privilege escalationCVE-2026-27112Criticalgithub.com/akuity/kargo: Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API EndpointsCVE-2026-27111Mediumgithub.com/akuity/kargo: Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API EndpointsCVE-2026-26958Lowfilippo.io/edwards25519: filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identityCVE-2026-26315Mediumgithub.com/ethereum/go-ethereum: Go Ethereum Improperly Validates the ECIES Public Key in RLPx HandshakeCVE-2026-26314Highgithub.com/ethereum/go-ethereum: Go Ethereum affected by DoS via malicious p2p messageCVE-2026-26313Mediumgithub.com/ethereum/go-ethereum: Go Ethereum affected by DoS via malicious p2p messageCVE-2026-26995Lowgithub.com/refraction-networking/utls: uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120CVE-2026-27017Lowgithub.com/refraction-networking/utls: uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrotsCVE-2026-26205Highgithub.com/open-policy-agent/opa-envoy-plugin: opa-envoy-plugin has an Authorization Bypass via Double-Slash Path Misinterpretation in input.parsed_pathCVE-2026-26201Highgithub.com/jm33-m0/emp3r0r/core: emp3r0r Affected by Concurrent Map Access DoS (panic/crash)CVE-2026-25766Mediumgithub.com/labstack/echo/v5: Echo has a Windows path traversal via backslash in middleware.Static default filesystemCVE-2026-25242Mediumgogs.io/gogs: Unauthenticated File Upload in GogsCVE-2026-25232Highgogs.io/gogs: Gogs has a Protected Branch Deletion Bypass in Web InterfaceCVE-2026-25229Mediumgogs.io/gogs: Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in GogsCVE-2026-25120Mediumgogs.io/gogs: Gogs Allows Cross-Repository Comment Deletion via DeleteCommentGHSA-HR7J-63V7-VJ7GHighpterodactyl/panel: Pterodactyl Panel's SFTP sessions remain active after user account deletion or password changeCVE-2025-14573Lowgithub.com/mattermost/mattermost/server/v8: Mattermost fails to enforce invite permissions when updating team settingsCVE-2025-14350Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate team membership when processing channel mentionsCVE-2025-13821Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to sanitize sensitive data in WebSocket messagesCVE-2026-0997Mediumgithub.com/mattermost/mattermost-plugin-zoom: Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

Stop the waste.
Protect your environment with Kodem.