Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-0999Mediumgithub.com/mattermost/mattermost/server/v8: Mattermost fails to properly validate login method restrictionsCVE-2026-0998Mediumgithub.com/mattermost/mattermost-plugin-zoom: Mattermost Plugin Zoom fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpointCVE-2026-26187Highgithub.com/treeverse/lakefs: lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory accessCVE-2026-20796Lowgithub.com/mattermost/mattermost-server: Mattermost doesn't properly validate channel membership at the time of data retrievalCVE-2026-22892Mediumgithub.com/mattermost/mattermost-server: Mattermost doesn't validate user permissions when creating Jira issues from Mattermost postsCVE-2025-67860Lowgithub.com/neuvector/scanner: NeuVector scanner insecurely handles passwords as command argumentsCVE-2026-26056Highgithub.com/yokecd/yoke: Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATCCVE-2026-26055Highgithub.com/yokecd/yoke: Unauthenticated Admission Webhook Endpoints in Yoke ATCCVE-2025-47911Mediumgolang.org/x/net/html: golang.org/x/net/html has a Quadratic Parsing Complexity issueCVE-2026-25949Highgithub.com/traefik/traefik/v3: Traefik: TCP readTimeout bypass via STARTTLS on PostgresCVE-2026-24895Highgithub.com/dunglas/frankenphp: FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHPCVE-2026-24894Highgithub.com/dunglas/frankenphp: FrankenPHP leaks session data between requests in worker modeCVE-2026-21438Mediumgithub.com/quic-go/webtransport-go: webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams MapCVE-2026-21435Mediumgithub.com/quic-go/webtransport-go: webtransport-go: CloseWithError can block indefinitelyCVE-2026-21434Mediumgithub.com/quic-go/webtransport-go: webtransport-go: Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION CapsuleCVE-2025-41117Mediumgithub.com/grafana/grafana: Grafana has a Cross-site Scripting issueCVE-2026-26190Criticalgithub.com/milvus-io/milvus: Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System CompromiseCVE-2026-25935Highcode.vikunja.io/api: Vikunja Vulnerable to XSS Via Task PreviewCVE-2026-26014Mediumgithub.com/pion/dtls/v2: Pion DTLS's usage of random nonce generation with AES GCM ciphers risks leaking the authentication keyCVE-2026-2303Mediumgo.mongodb.org/mongo-driver: mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error HandlingCVE-2026-25934Mediumgithub.com/go-git/go-git/v5: go-git improperly verifies data integrity values for .idx and .pack filesCVE-2026-25890Highgithub.com/filebrowser/filebrowser/v2: File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLCVE-2026-25889Mediumgithub.com/filebrowser/filebrowser/v2: File Browser has an Authentication Bypass in User Password UpdateCVE-2025-66630Criticalgithub.com/gofiber/fiber/v2: Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failureCVE-2026-25791Highgithub.com/bishopfox/sliver: Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service

Stop the waste.
Protect your environment with Kodem.