Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54068Mediumgithub.com/siyuan-note/siyuan/kernel: SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIconCVE-2026-54063Highgithub.com/xuri/excelize/v2: Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)CVE-2026-54072Criticalgithub.com/authorizerdev/authorizer: Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URLCVE-2026-54067Criticalgithub.com/siyuan-note/siyuan/kernel: SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()CVE-2026-54066Highgithub.com/siyuan-note/siyuan/kernel: SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894 CVE-2026-49838Mediumgithub.com/osrg/gobgp/v4: GoBGP confederation validation panics on empty AS_PATH attributeCVE-2026-49837Mediumgithub.com/osrg/gobgp/v4: GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundariesCVE-2026-49834Mediumgithub.com/sigstore/sigstore-go: sigstore-go has a multi-log threshold bypass via single compromised logCVE-2026-55252Mediumgithub.com/openrundev/openrun: OpenRun: Redirect URL validation bypass using  //host  paths leads to Open RedirectCVE-2026-53602Mediumgithub.com/forgekeep/nebula-mesh: nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificateCVE-2026-50553Highgithub.com/enchant97/note-mark/backend: Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)CVE-2026-50554Mediumgithub.com/enchant97/note-mark/backend: Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public booksCVE-2026-53649Criticalgithub.com/BishopFox/joro: Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCECVE-2026-52831Criticalgithub.com/nuclio/nuclio: Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCECVE-2026-50197Highgithub.com/zalando/skipper: Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requestsCVE-2026-53508Mediumgithub.com/oasdiff/oasdiff: oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)CVE-2026-53572Mediumgithub.com/kedacore/keda/v2: KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escapingCVE-2026-53553Highgithub.com/zhenorzz/goploy: Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server CompromiseCVE-2026-53552Criticalgithub.com/zhenorzz/goploy: Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlersCVE-2026-53487Mediumgithub.com/zxh326/kite: Kite has an authenticated cluster RBAC bypass in /api/v1/overviewGHSA-7856-G3GV-9WQ8Lowgithub.com/tinfoil-factory/netfoil: netfoil: Attacker controlled data written to logsGHSA-3G4Q-2F67-2GVHLowgithub.com/tinfoil-factory/netfoil: netfoil has a resource leak in LRU cacheGHSA-59QP-CFJ3-RP64Mediumgithub.com/tinfoil-factory/netfoil: netfoil has a domain name filter bypass via multiple questionsCVE-2026-44342Mediumgithub.com/QuantumNous/new-api: New API is vulnerable to CSRF through user email bindingCVE-2026-33655Highgithub.com/QuantumNous/new-api: New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

Stop the waste.
Protect your environment with Kodem.