Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55513Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokensCVE-2026-55512Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingCVE-2026-54629Highgithub.com/julien040/anyquery: Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeCVE-2026-53603Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: Operator session tokens stored in plaintext in the databaseCVE-2026-53604Highgithub.com/forgekeep/nebula-mesh: nebula-mesh: CA private key not zeroized on web mobile-bundle error pathsCVE-2026-54628Highgithub.com/julien040/anyquery: Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server ModeGHSA-MQXV-9RM6-W8QCHighgithub.com/lin-snow/ech0: Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.MiddlewareCVE-2026-54448Highgithub.com/aquasecurity/trivy: Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parserGHSA-PQG7-V6WH-3PFPHighgithub.com/almeidapaulopt/tsdproxy: TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend servicesCVE-2026-50158Highgithub.com/eat-pray-ai/yutu: yutu: Arbitrary File Write via MCP `caption-download` ToolCVE-2026-50141Highgo.woodpecker-ci.org/woodpecker/v3: Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonationCVE-2026-50006Criticalgithub.com/julien040/anyquery: Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeCVE-2026-50125Highgithub.com/StacklokLabs/mkp: MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory ExhaustionCVE-2026-50018Mediumgithub.com/SpectoLabs/hoverfly: Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve ActionsCVE-2026-50013Highgithub.com/SpectoLabs/hoverfly: Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff ModeCVE-2026-54250Mediumgithub.com/k3s-io/k3s: K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot DecompressionCVE-2026-44300Highgithub.com/opencost/opencost: OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/InjectionGHSA-G936-7JQJ-MWV8Criticalgithub.com/almeidapaulopt/tsdproxy: TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalationCVE-2026-54174Highchainguard.dev/apko: melange: Incomplete package integrity verification allows data section substitutionCVE-2026-50551Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell ContentCVE-2026-54158Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()CVE-2026-54088Criticalgithub.com/filebrowser/filebrowser/v2: File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)CVE-2026-54070Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS in Bazaar marketplace via package README event handlersCVE-2026-54089Criticalgithub.com/filebrowser/filebrowser/v2: File Browser: Authentication Bypass via Proxy Auth Header ForgeryCVE-2026-54069Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

Stop the waste.
Protect your environment with Kodem.