Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55477Highgithub.com/mhsanaei/3x-ui/v3: 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path ManipulationGHSA-W67G-5RQW-F597Mediumgithub.com/gorilla/websocket: Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask KeyGHSA-4PH6-MJV7-3FQ6Lowgithub.com/tinfoil-factory/netfoil: netfoil vulnerable to improper handling of untrusted DoH response dataCVE-2026-77354Highgithub.com/getkin/kin-openapi: kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decodingCVE-2026-76905Highgithub.com/getkin/kin-openapi: kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoSCVE-2026-64679Highgithub.com/runatlantis/atlantis: Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/CreationCVE-2026-67448Mediumgithub.com/axllent/mailpit: Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)CVE-2026-67447Mediumgithub.com/axllent/mailpit: Mailpit: SMTP DATA line reader buffers over-limit input before size enforcementGHSA-RXHG-VCWW-2MPWLowgithub.com/fleetdm/fleet/v4: Fleet: ORDER BY column injection on activity list endpointsGHSA-Q9C5-PP7M-FM2GMediumgithub.com/fleetdm/fleet/v4: Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLsCVE-2026-54245Highgithub.com/fleetdm/fleet: Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet databaseCVE-2026-54168Mediumgithub.com/openshift-pipelines/pipelines-as-code: Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task…CVE-2026-54167Highgithub.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host headerGHSA-22W5-2FXG-VRWXLowgithub.com/opentofu/opentofu: OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or…CVE-2026-54162Mediumgithub.com/alexandre-daubois/ember: Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUIGHSA-H58C-XCCX-75M3Lowgithub.com/coder/coder/v2: Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settingsGHSA-8FXQ-53RX-PH5FLowgithub.com/coder/coder/v2: Coder: Login endpoint user enumeration via timing-defense placeholder in password comparisonCVE-2026-54061Criticalgithub.com/dgraph-io/dgraph/v25: Dgraph Alpha group stores can be replaced via unauthenticated external snapshot importCVE-2026-55149Highgithub.com/vouch/vouch-proxy: vouch-proxy has an Unbounded Multipart Cookie Allocation DoSCVE-2026-45404Mediumgo.opentelemetry.io/otel/bridge/opentracing: OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent accessCVE-2026-32637Mediumgithub.com/vmware-tanzu/velero: Velero vulnerable to file path traversal when extracting from backup's tarballCVE-2026-61712Lowgithub.com/moby/buildkit: BuildKit has a possible runtime DoS via unbounded group parsingCVE-2026-61711Mediumgithub.com/moby/buildkit: BuildKit: Custom frontend could bypass Seccomp/AppArmorCVE-2026-53941Mediumgithub.com/inspektor-gadget/inspektor-gadget: Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoSCVE-2026-17106Highgithub.com/moby/go-archive: moby/go-archive: Crafted tar archive can write outside the extraction directory

Stop the waste.
Protect your environment with Kodem.