Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-21696Highgithub.com/pterodactyl/wings: Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being consideredCVE-2025-69199Highgithub.com/pterodactyl/wings: Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacksCVE-2026-23742Highgithub.com/zalando/skipper: Skipper is vulnerable to arbitrary code execution through lua filtersCVE-2026-23645Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan Has a Stored Cross-Site Scripting (XSS) Vulnerability via Unrestricted SVG File UploadCVE-2025-14435Mediumgithub.com/mattermost/mattermost-server: Mattermost is vulnerable to DoS due to infinite re-renders on API errorsCVE-2025-14822Lowgithub.com/mattermost/mattermost-server: Mattermost is vulnerable to CPU exhaustion via crafted HTTP requestCVE-2026-22045Mediumgithub.com/traefik/traefik/v3: Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallCVE-2025-68671Mediumgithub.com/treeverse/lakefs: lakeFS is Missing Timestamp Validation in S3 Gateway AuthenticationCVE-2026-23520Criticalgithub.com/getarcaneapp/arcane/backend: Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCECVE-2026-23511Mediumgithub.com/zitadel/zitadel: Zitadel has a user enumeration vulnerability in Login UIsCVE-2025-66292Highgithub.com/donknap/dpanel: DPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interfaceCVE-2025-69725Mediumgithub.com/go-chi/chi/v5: chi has an open redirect vulnerability in the RedirectSlashes middlewareCVE-2026-22868Highgithub.com/ethereum/go-ethereum: go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p messageCVE-2026-22862Highgithub.com/ethereum/go-ethereum: go-ethereum is vulnerable to DoS via malicious p2p message affecting a vulnerable nodeCVE-2026-0528Mediumgithub.com/elastic/beats/v7: Metricbeat affected by multiple denial of service vulnerabilitiesCVE-2026-22786Highgithub.com/flipped-aurora/gin-vue-admin: Gin-vue-admin has arbitrary file upload vulnerability caused by path traversalCVE-2026-22772Mediumgithub.com/sigstore/fulcio: Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex BypassCVE-2026-22771Highgithub.com/envoyproxy/gateway: Envoy Extension Policy lua scripts injection causes arbitrary command executionCVE-2026-22689Mediumgithub.com/axllent/mailpit: Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emailsCVE-2026-22703Mediumgithub.com/sigstore/cosign/v3: Cosign verification accepts any valid Rekor entry under certain conditionsCVE-2025-60538Mediumgithub.com/go-shiori/shiori: Shiori is vulnerable to authentication bypass via a brute force attackCVE-2026-22688Criticalgithub.com/Tencent/WeKnora: WeKnora has Command Injection in MCP stdio testCVE-2026-22687Mediumgithub.com/Tencent/WeKnora: WeKnora vulnerable to SQL InjectionCVE-2026-22253Mediumgithub.com/charmbracelet/soft-serve: Soft Serve is missing an authorization check in LFS lock deletionCVE-2025-68151Mediumgithub.com/coredns/coredns: CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

Stop the waste.
Protect your environment with Kodem.