Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-61711Mediumgithub.com/moby/buildkit: BuildKit: Custom frontend could bypass Seccomp/AppArmorCVE-2026-53941Mediumgithub.com/inspektor-gadget/inspektor-gadget: Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoSCVE-2026-17106Highgithub.com/moby/go-archive: moby/go-archive: Crafted tar archive can write outside the extraction directoryCVE-2026-65959Mediumvitess.io/vitess: Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL dataCVE-2026-63328Mediumgithub.com/aquasecurity/trivy: Trivy Plugin Manager has Path Traversal that Allows Arbitrary File WriteGHSA-MPWR-8VM7-H73FMediumsoftware.sslmate.com/src/go-pkcs12: package pkcs12: Authentication bypass in Decode functionsGHSA-FHGH-WQ4Q-R37XHighgitlab.com/uniget-org/cli: uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is setCVE-2026-55062Mediumgitlab.com/uniget-org/cli: uniget CLI has Path Traversal in Hook Files - Directory Escape VulnerabilityCVE-2026-55061Mediumgitlab.com/uniget-org/cli: uniget CLI has an EDITOR Command InjectionCVE-2026-45099Mediumgithub.com/gruntwork-io/terragrunt: Terragrunt: Arbitrary File Deletion via Malicious Module ManifestCVE-2026-64865Mediumgithub.com/QuantumNous/new-api: New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypassCVE-2026-71479Criticalgithub.com/QuantumNous/new-api: New API: Integer overflow in quota billing yields negative charges (self-crediting)CVE-2026-64866Mediumgithub.com/QuantumNous/new-api: New API: Admin can reset passkeys for same-level or higher-privileged usersCVE-2026-64868Highgithub.com/QuantumNous/new-api: New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body loggingCVE-2026-64859Criticalgithub.com/QuantumNous/new-api: New API: User List API Leaks Root User Access Token Leading to Privilege EscalationCVE-2026-53658Mediumgithub.com/hyperledger/fabric-ca: Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser FilterCVE-2026-53657Highgithub.com/lima-vm/lima/v2: Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketCVE-2026-35511Highgithub.com/authorizerdev/authorizer: Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accountsCVE-2026-54526Highgithub.com/argoproj/argo-workflows/v4: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)CVE-2026-54917Highgithub.com/seaweedfs/seaweedfs: SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessCVE-2026-48786Mediumgithub.com/fleetdm/fleet/v4: Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointCVE-2026-73080Criticalgithub.com/seaweedfs/seaweedfs: SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedleCVE-2026-71557Mediumgithub.com/go-git/go-git/v5: go-git: Malicious reference names may modify files outside the reference storageCVE-2026-71556Highgithub.com/go-git/go-git/v5: go-git: Worktree operations may follow symlinksCVE-2026-54763Highgithub.com/traefik/traefik/v2: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth /…

Stop the waste.
Protect your environment with Kodem.