Package ecosystem
Go package vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 1,221 vulnerabilities in Go packages: 35 in the last 7 days and 572 in the last 90 days, 168 of them critical and 2 exploited in the wild. The most recent, CVE-2026-62286, was published on 24 September 2026. 132 packages have a page of their own.
- Last 7 days
- 35
- Last 90 days
- 572
- Critical, all time
- 168
- Exploited in the wild
- 2
About Go
An open-source programming language supported by Google.
Go packages
- github.com/siyuan-note/siyuan/kernel (Go)83
- code.gitea.io/gitea (Go)76
- github.com/rclone/rclone (Go)26
- gogs.io/gogs (Go)25
- github.com/filebrowser/filebrowser/v2 (Go)18
- github.com/fission/fission (Go)18
- github.com/klever-io/klever-go (Go)18
- code.vikunja.io/api (Go)15
- github.com/cloudreve/Cloudreve/v4 (Go)15
- github.com/gotenberg/gotenberg/v8 (Go)14
- github.com/nezhahq/nezha (Go)14
- github.com/fleetdm/fleet/v4 (Go)13
- github.com/juev/nebula-mesh (Go)12
- github.com/casdoor/casdoor (Go)11
- github.com/traefik/traefik/v3 (Go)11
- go.opentelemetry.io/obi (Go)11
- golang.org/x/crypto/ssh (Go)11
- github.com/axllent/mailpit (Go)10
- github.com/lxc/incus/v7/cmd/incusd (Go)10
- github.com/patrickhener/goshs/v2 (Go)10
- github.com/rabbitmq/amqp091-go (Go)10
- github.com/zitadel/zitadel (Go)10
- gitea.dev (Go)9
- github.com/0xJacky/Nginx-UI (Go)9
- github.com/cloudreve/Cloudreve/v3 (Go)9
- github.com/free5gc/udr (Go)9
- github.com/kyverno/kyverno (Go)9
- github.com/omec-project/amf (Go)9
- github.com/patrickhener/goshs (Go)9
- github.com/QuantumNous/new-api (Go)9
- github.com/lin-snow/ech0 (Go)8
- github.com/openbao/openbao (Go)8
- github.com/projectcapsule/capsule (Go)8
- goshs.de/goshs/v2 (Go)8
- github.com/apache/incubator-answer (Go)7
- github.com/argoproj/argo-workflows/v4 (Go)7
- github.com/caddyserver/caddy/v2 (Go)7
- github.com/enchant97/note-mark/backend (Go)7
- github.com/forgekeep/nebula-mesh (Go)7
- github.com/free5gc/nef (Go)7
- github.com/getarcaneapp/arcane/backend (Go)7
- github.com/go-git/go-git/v5 (Go)7
- github.com/go-git/go-git/v6 (Go)7
- github.com/gohugoio/hugo (Go)7
- github.com/projectdiscovery/nuclei/v3 (Go)7
- github.com/traefik/traefik/v2 (Go)7
- github.com/xyproto/algernon (Go)7
- oras.land/oras-go/v2 (Go)7
- github.com/filebrowser/filebrowser (Go)6
- github.com/googleapis/mcp-toolbox (Go)6
- github.com/OliveTin/OliveTin (Go)6
- github.com/openfga/openfga (Go)6
- github.com/seaweedfs/seaweedfs (Go)6
- github.com/authzed/spicedb (Go)5
- github.com/containers/podman/v5 (Go)5
- github.com/gtsteffaniak/filebrowser/backend (Go)5
- github.com/hatchet-dev/hatchet (Go)5
- github.com/juju/juju (Go)5
- github.com/modelcontextprotocol/registry (Go)5
- github.com/oauth2-proxy/oauth2-proxy/v7 (Go)5
- github.com/openziti/zrok (Go)5
- github.com/openziti/zrok/v2 (Go)5
- github.com/pterodactyl/wings (Go)5
- github.com/tektoncd/pipeline (Go)5
- github.com/tinfoil-factory/netfoil (Go)5
- github.com/zalando/skipper (Go)5
- chainguard.dev/apko (Go)4
- crypto (Go)4
- github.com/amir20/dozzle (Go)4
- github.com/argoproj/argo-workflows/v3 (Go)4
- github.com/canonical/lxd (Go)4
- github.com/containers/podman/v4 (Go)4
- github.com/coredns/coredns (Go)4
- github.com/dadrus/heimdall (Go)4
- github.com/daytonaio/daytona (Go)4
- github.com/docker/docker (Go)4
- github.com/free5gc/pcf (Go)4
- github.com/getkin/kin-openapi (Go)4
- github.com/hahwul/dalfox/v2 (Go)4
- github.com/hashicorp/vault (Go)4
- github.com/julien040/anyquery (Go)4
- github.com/kubev2v/migration-planner (Go)4
- github.com/moby/moby (Go)4
- github.com/moby/moby/v2 (Go)4
- github.com/neuvector/neuvector (Go)4
- github.com/nhost/nhost (Go)4
- github.com/nuclio/nuclio (Go)4
- github.com/obot-platform/obot (Go)4
- github.com/oxia-db/oxia (Go)4
- github.com/shellhub-io/shellhub (Go)4
- github.com/tomwright/dasel/v3 (Go)4
- github.com/traefik/traefik (Go)4
- gitlab.com/uniget-org/cli (Go)4
- golang.org/x/crypto/ssh/agent (Go)4
- goshs.de/goshs (Go)4
- k8s.io/kubernetes (Go)4
- www.velocidex.com/golang/velociraptor (Go)4
- github.com/anchore/quill (Go)3
- github.com/aquasecurity/trivy (Go)3
- github.com/basekick-labs/arc (Go)3
- github.com/caddyserver/caddy (Go)3
- github.com/dgraph-io/dgraph/v25 (Go)3
- github.com/ellanetworks/core (Go)3
- github.com/free5gc/amf (Go)3
- github.com/free5gc/ausf (Go)3
- github.com/free5gc/smf (Go)3
- github.com/go-chi/chi/v5/middleware (Go)3
- github.com/gofiber/fiber/v3 (Go)3
- github.com/grafana/grafana (Go)3
- github.com/gtsteffaniak/filebrowser (Go)3
- github.com/inspektor-gadget/inspektor-gadget (Go)3
- github.com/iskorotkov/avro/v2 (Go)3
- github.com/jackc/pgx/v5 (Go)3
- github.com/kata-containers/kata-containers (Go)3
- github.com/lf-edge/ekuiper/v2 (Go)3
- github.com/lucasdillmann/nginx-ignition (Go)3
- github.com/moby/buildkit (Go)3
- github.com/ollama/ollama (Go)3
- github.com/openclaw/crabbox (Go)3
- github.com/OpenListTeam/OpenList/v4 (Go)3
- github.com/osrg/gobgp/v4 (Go)3
- github.com/perses/perses (Go)3
- github.com/pocket-id/pocket-id/backend (Go)3
- github.com/semaphoreui/semaphore (Go)3
- github.com/sonirico/mcp-shell (Go)3
- github.com/stacklok/toolhive (Go)3
- github.com/tilt-dev/tilt (Go)3
- github.com/xuri/excelize/v2 (Go)3
- go (Go)3
- go.senan.xyz/gonic (Go)3
- google.golang.org/grpc (Go)3
- helm.sh/helm/v4 (Go)3
Latest Go package vulnerabilities
- CVE-2026-62286: Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a…mediumCVSS 4.3EPSS 0.3%
- CVE-2026-85057: ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the…highCVSS 8.7EPSS 0.4%
- CVE-2026-85056: ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser…highCVSS 8.2EPSS 0.3%
- CVE-2026-61604: The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds…criticalCVSS 0EPSS 0.3%
- CVE-2026-19730: Podman quadlet install incomplete file truncationmediumCVSS 4.2EPSS 0.2%
- CVE-2026-86065: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe…highCVSS 7.5EPSS 0.4%
- CVE-2026-86064: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket…highCVSS 8.6EPSS 0.4%
- CVE-2026-82409: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go…highCVSS 7.5EPSS 0.3%
- CVE-2026-82407: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go…highEPSS 0.4%
- CVE-2026-82406: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function…highCVSS 7.5EPSS 0.3%
- CVE-2026-82405: Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission…highCVSS 9.1EPSS 0.3%
- CVE-2026-77322: SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go…highCVSS 7.5EPSS 0.5%
- CVE-2026-58268: SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in…highCVSS 7.5EPSS 0.6%
- CVE-2026-76819: Rejected reason: Further research determined the issue results from a dependency.highCVSS 8.6
- CVE-2026-76805: Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-76804: Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading…mediumCVSS 5.5EPSS 0.2%
- CVE-2026-76803: Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript…mediumCVSS 5.3EPSS 0.4%
- CVE-2026-76802: Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading…mediumCVSS 4.7EPSS 0.2%
- CVE-2026-79913: Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-77637: Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in…lowCVSS 3.8EPSS 0.3%
- CVE-2026-77633: Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in…highCVSS 7.1EPSS 0.4%
- Falco k8saudit detection bypass for privileged init and ephemeral containersmediumCVSS 4.3
- CVE-2026-77582: Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing…mediumEPSS 0.5%
- CVE-2026-77561: Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-77560: Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames…highCVSS 8.1EPSS 0.6%
Most severe Go package vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.criticalexploited in the wildCVSS 9.8EPSS 24.0%
- CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerabilitycriticalexploited in the wildCVSS 8.1
- CVE-2026-69084: SiYuan arbitrary SQL execution via searchEmbedBlockcriticalCVSS 10EPSS 1.6%
- CVE-2026-52831: Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio…criticalCVSS 10EPSS 0.5%
- CVE-2026-69083: SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakoutcriticalCVSS 10EPSS 0.5%
- CVE-2026-46695: boxlite-ai Boxlite read-only volume bypass via CAP_SYS_ADMINcriticalCVSS 10EPSS 0.5%
- CVE-2026-72811: SiYuan backlink search SQL injection via unescaped metadata concatenationcriticalCVSS 10EPSS 0.4%
- CVE-2026-46595: Go x/crypto authorization bypass in SSH server source-address validationcriticalCVSS 10EPSS 0.4%
- CVE-2026-45087: hahwul Dalfox unauthenticated RCE in REST API server modecriticalCVSS 10EPSS 0.1%
- CVE-2026-44329: free5GC SMF missing authentication in UPI management interfacecriticalCVSS 10EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 52 | 10 | |
| 6 Jul 2026 | 38 | 3 | |
| 13 Jul 2026 | 31 | 1 | |
| 20 Jul 2026 | 76 | 4 | |
| 27 Jul 2026 | 41 | 6 | |
| 3 Aug 2026 | 24 | 3 | |
| 10 Aug 2026 | 29 | 3 | |
| 17 Aug 2026 | 49 | 10 | |
| 24 Aug 2026 | 37 | 5 | |
| 31 Aug 2026 | 53 | 7 | |
| 7 Sep 2026 | 33 | 5 | |
| 14 Sep 2026 | 74 | 5 | |
| 21 Sep 2026 | 35 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/go.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Go package vulnerabilities", https://junglewise.ai/threats/vendors/go, 26 September 2026.