Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-25059Highgithub.com/OpenListTeam/OpenList/v4: OpenList vulnerable to Path Traversal in file copy and remove handlersCVE-2025-67601Highgithub.com/rancher/rancher: Rancher CLI skips TLS verification on Rancher CLI login commandCVE-2026-24846Mediumgithub.com/chainguard-dev/malcontent: malcontent vulnerable to symlink Path Traversal via handleSymlink argument confusion in archive extractionCVE-2026-24845Mediumgithub.com/chainguard-dev/malcontent: malcontent OCI image pull credential exfiltration via malicious registry token realmCVE-2026-1237Lowgithub.com/juju/juju: Juju has broken CMR authorizationCVE-2026-25539Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCECVE-2026-25992Highgithub.com/siyuan-note/siyuan/kernel: SiYuan File Read API Case Sensitivity Bypass can Lead to Path TraversalCVE-2026-24748Mediumgithub.com/akuity/kargo: Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated accessCVE-2026-23881Highgithub.com/kyverno/kyverno: Kyverno Denial of Service via Context Variable Amplification in Policy EngineCVE-2026-22039Criticalgithub.com/kyverno/kyverno: Kyverno Cross-Namespace Privilege Escalation via Policy apiCallCVE-2026-24738Mediumgithub.com/gmrtd/gmrtd: gmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length ValuesCVE-2026-24740Highgithub.com/amir20/dozzle: Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell AccessCVE-2026-24686Mediumgithub.com/theupdateframework/go-tuf/v2: go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository NamesCVE-2026-24470Highgithub.com/zalando/skipper: Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalNameCVE-2025-14525Mediumkubevirt.io/kubevirt: KubeVirt Guest Agent DoS via Excessive Network Interface ReportsCVE-2025-66719Criticalgithub.com/free5gc/nrf: Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF valueGHSA-C32P-WCQJ-J677Highgithub.com/cometbft/cometbft: CometBFT has inconsistencies between how commit signatures are verified and how block time is derivedCVE-2026-20904Mediumgithub.com/go-gitea/gitea: Gitea does not properly validate ownership when toggling OpenID URI visibilityCVE-2026-20912Mediumgithub.com/go-gitea/gitea: Gitea does not properly validate repository ownership when linking attachments to releasesCVE-2026-20736Lowcode.gitea.io/gitea: Gitea has improper access control for uploaded attachmentsCVE-2026-20897Mediumgithub.com/go-gitea/gitea: Gitea does not properly validate repository ownership when deleting Git LFS locksCVE-2026-20888Mediumgithub.com/go-gitea/gitea: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interfaceCVE-2026-20800Lowgithub.com/go-gitea/gitea: Gitea improperly exposes issue and pull request titlesCVE-2026-20750Mediumgithub.com/go-gitea/gitea: Gitea does not properly validate project ownership in organization project operationsCVE-2026-20883Lowgithub.com/go-gitea/gitea: Gitea improperly exposes issue titles and repository names through previously started stopwatches

Stop the waste.
Protect your environment with Kodem.