Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-0798Lowcode.gitea.io/gitea: Gitea may send release notification emails for private repositories to users whose access has been revokedCVE-2026-24137Mediumgithub.com/sigstore/sigstore: sigstore legacy TUF client allows for arbitrary file writes with target cache path traversalCVE-2026-23954Highgithub.com/lxc/incus/v6/cmd/incusd: Incus container image templating arbitrary host file read and writeCVE-2026-23953Highgithub.com/lxc/incus/v6: Incus container environment configuration newline injectionCVE-2026-24117Mediumgithub.com/sigstore/rekor: Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URLCVE-2026-23831Mediumgithub.com/sigstore/rekor: Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty MessageCVE-2025-69820Mediumgithub.com/beam-cloud/beta9: Beam Exposes sensitive information via joinCleanPath functionCVE-2026-24124Highd7y.io/dragonfly/v2: Dragonfly Manager Job API Unauthenticated AccessCVE-2026-24058Highgithub.com/charmbracelet/soft-serve: Soft Serve Affected by an Authentication BypassGHSA-R92C-9C7F-3PJ8Lowgithub.com/opentofu/opentofu: OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip formatCVE-2026-23990Mediumgithub.com/controlplaneio-fluxcd/flux-operator: Flux Operator Web UI Impersonation Bypass via Empty OIDC ClaimsCVE-2026-23960Highgithub.com/argoproj/argo-workflows/v3: Argo Workflows affected by stored XSS in the artifact directory listingCVE-2026-23992Mediumgithub.com/theupdateframework/go-tuf/v2: go-tuf improperly validates the configured threshold for delegationsCVE-2026-23991Mediumgithub.com/theupdateframework/go-tuf/v2: go-tuf affected by client DoS via malformed server responseCVE-2026-23849Mediumgithub.com/filebrowser/filebrowser: File Browser Vulnerable to Username Enumeration via Timing Attack in /api/loginCVE-2026-23850Highgithub.com/siyuan-note/siyuan/kernel: SiYuan vulnerable to Arbitrary file Read / SSRFCVE-2026-23851Highgithub.com/siyuan-note/siyuan/kernel: SiYuan Vulnerable to Arbitrary File Read via File Copy FunctionalityCVE-2026-23845Mediumgithub.com/axllent/mailpit: Mailpit has a Server-Side Request Forgery (SSRF) via HTML Check APICVE-2026-23847Lowgithub.com/siyuan-note/siyuan/kernel: SiYuan has a Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIconCVE-2026-23518Criticalgithub.com/fleetdm/fleet: Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment CVE-2026-23517Highgithub.com/fleetdm/fleet: Fleet has an Access Control vulnerability in debug/pprof endpointsCVE-2026-22808Mediumgithub.com/fleetdm/fleet: Fleet Windows MDM endpoint has a Cross-site Scripting vulnerabilityCVE-2026-23829Mediumgithub.com/axllent/mailpit: Mailpit has an SMTP Header Injection via Regex BypassCVE-2026-23644Highgithub.com/esm-dev/esm.sh: esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packagesCVE-2026-22822Criticalgithub.com/external-secrets/external-secrets: External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function

Stop the waste.
Protect your environment with Kodem.