go
OSS Librariespackage-ecosystem
Latest CVEs
The 15 most recently published vulnerabilities affecting go.
- GHSA-jhjp-4c2q-xmx4k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers
- GHSA-jgh3-fggc-mcpmObot: Server-Side Request Forgery via remote MCP server URL
- GHSA-pr6h-vr44-xq8jObot: MCP Registry API readable without authentication
- GHSA-xwmw-prc4-v3crObot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
- CVE-2026-78427Admission Control Bypass via Hardcoded Sidecar Image Exemption4.3
- CVE-2026-78425SAML Audience Confusion Allows Cross-SP Authentication
- CVE-2026-78426Logout bypass via alternate JWT spelling3.7
- CVE-2026-78428Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently8.0
- GHSA-rf68-8gjr-36q7Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
- GHSA-hxjg-93wc-h8p8Komari: Management Interface CSRF
- GHSA-57v5-wqx3-cgj4SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
- GHSA-7j72-f6wg-cxw6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
- GHSA-gw25-m53r-qh88SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
- GHSA-99rq-75j6-5j9fSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
- GHSA-mf7q-r4rv-jv94Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check