{"schema_version":1,"title":"Go package vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5,278 vulnerabilities in Go packages: 39 in the last 7 days and 847 in the last 90 days, 213 of them critical and 6 exploited in the wild. The most recent, CVE-2026-94445, was published on 25 September 2026. 132 packages have a page of their own.","url":"https://junglewise.ai/threats/vendors/go","json_url":"https://junglewise.ai/threats/vendors/go.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/go","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":633,"all_time":5278,"critical":213,"exploited":6,"last_7_days":39,"last_30_days":250,"last_90_days":847,"last_365_days":2631},"latest":[{"cve":"CVE-2026-94445","cvss":8.8,"slug":"cve-2026-94445-a-malicious-txtar-could-escape-the-intended-execution-context-and","title":"Go playground arbitrary write and code execution","severity":"high","exploited":false,"published_at":"2026-09-25T17:17:19.963+00:00","url":"https://junglewise.ai/threats/cve-2026-94445-a-malicious-txtar-could-escape-the-intended-execution-context-and"},{"cve":"CVE-2026-62286","cvss":4.3,"epss":0.0034,"slug":"cve-2026-62286-dozzle-label-filter-bypass-in-events-stream","title":"Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's l","severity":"medium","exploited":false,"published_at":"2026-09-24T19:17:15.657+00:00","url":"https://junglewise.ai/threats/cve-2026-62286-dozzle-label-filter-bypass-in-events-stream"},{"cve":"CVE-2026-85057","cvss":8.7,"epss":0.0039,"slug":"cve-2026-85057-zitadel-actions-v1-sandbox-escape-via-require-filesystem-read","title":"ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compati","severity":"high","exploited":false,"published_at":"2026-09-24T18:19:04.217+00:00","url":"https://junglewise.ai/threats/cve-2026-85057-zitadel-actions-v1-sandbox-escape-via-require-filesystem-read"},{"cve":"CVE-2026-85056","cvss":8.2,"epss":0.0029,"slug":"cve-2026-85056-zitadel-login-v2-mfa-bypass-via-session-reuse","title":"ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password v","severity":"high","exploited":false,"published_at":"2026-09-24T18:19:04.04+00:00","url":"https://junglewise.ai/threats/cve-2026-85056-zitadel-login-v2-mfa-bypass-via-session-reuse"},{"cve":"CVE-2026-61604","cvss":4,"epss":0.0027,"slug":"cve-2026-61604-ixo-blockchain-x-bonds-did-resolved-payer-authorization-bypass","title":"The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds fro","severity":"critical","exploited":false,"published_at":"2026-09-24T18:17:15.707+00:00","url":"https://junglewise.ai/threats/cve-2026-61604-ixo-blockchain-x-bonds-did-resolved-payer-authorization-bypass"},{"cve":"CVE-2026-19730","cvss":4.2,"epss":0.0016,"slug":"cve-2026-19730-podman-quadlet-install-incomplete-file-truncation","title":"Podman quadlet install incomplete file truncation","severity":"medium","exploited":false,"published_at":"2026-09-24T16:28:26+00:00","url":"https://junglewise.ai/threats/cve-2026-19730-podman-quadlet-install-incomplete-file-truncation"},{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-82409","cvss":4,"epss":0.0027,"slug":"cve-2026-82409-klever-go-elasticsearch-injection-via-account-name","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts pla","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.893+00:00","url":"https://junglewise.ai/threats/cve-2026-82409-klever-go-elasticsearch-injection-via-account-name"},{"cve":"CVE-2026-82407","cvss":4,"epss":0.0043,"slug":"cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the r","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.707+00:00","url":"https://junglewise.ai/threats/cve-2026-82407-klever-go-bls-public-key-validation-bypass-in-validator"},{"cve":"CVE-2026-82406","cvss":4,"epss":0.0034,"slug":"cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/mark","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.547+00:00","url":"https://junglewise.ai/threats/cve-2026-82406-klever-go-marketplace-buy-missing-isclaimed-guard"},{"cve":"CVE-2026-82405","cvss":4,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"},{"cve":"CVE-2026-77322","cvss":7.5,"epss":0.0052,"slug":"cve-2026-77322-sipgo-dos-via-unvalidated-websocket-frame-length","title":"SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Re","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:08.2+00:00","url":"https://junglewise.ai/threats/cve-2026-77322-sipgo-dos-via-unvalidated-websocket-frame-length"},{"cve":"CVE-2026-58268","cvss":7.5,"epss":0.0061,"slug":"cve-2026-58268-sipgo-dos-via-unvalidated-content-length-in-stream-parser","title":"SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a","severity":"high","exploited":false,"published_at":"2026-09-22T20:17:03.96+00:00","url":"https://junglewise.ai/threats/cve-2026-58268-sipgo-dos-via-unvalidated-content-length-in-stream-parser"},{"cve":"CVE-2026-76819","cvss":8.6,"slug":"cve-2026-76819-projectdiscovery-nuclei-arbitrary-code-execution-via-goja","title":"Rejected reason: Further research determined the issue results from a dependency.","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:25.23+00:00","url":"https://junglewise.ai/threats/cve-2026-76819-projectdiscovery-nuclei-arbitrary-code-execution-via-goja"},{"cve":"CVE-2026-76805","cvss":5.3,"epss":0.0041,"slug":"cve-2026-76805-nuclei-environment-variable-disclosure-in-dast-fuzz-mode","title":"Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:25.087+00:00","url":"https://junglewise.ai/threats/cve-2026-76805-nuclei-environment-variable-disclosure-in-dast-fuzz-mode"},{"cve":"CVE-2026-76804","cvss":5.5,"epss":0.0017,"slug":"cve-2026-76804-projectdiscovery-nuclei-security-gate-bypass-via-workflow-file","title":"Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enf","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:24.943+00:00","url":"https://junglewise.ai/threats/cve-2026-76804-projectdiscovery-nuclei-security-gate-bypass-via-workflow-file"},{"cve":"CVE-2026-76803","cvss":5.3,"epss":0.004,"slug":"cve-2026-76803-projectdiscovery-nuclei-local-file-read-via-mysql-sandbox-bypass","title":"Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not en","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:24.797+00:00","url":"https://junglewise.ai/threats/cve-2026-76803-projectdiscovery-nuclei-local-file-read-via-mysql-sandbox-bypass"},{"cve":"CVE-2026-76802","cvss":4.7,"epss":0.0018,"slug":"cve-2026-76802-projectdiscovery-nuclei-arbitrary-command-execution-in-dast","title":"Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:24.627+00:00","url":"https://junglewise.ai/threats/cve-2026-76802-projectdiscovery-nuclei-arbitrary-command-execution-in-dast"},{"cve":"CVE-2026-88010","cvss":4,"epss":0.0069,"slug":"cve-2026-88010-traefik-basicauth-singleflight-username-enumeration-via-timing","title":"Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.g","severity":"medium","exploited":false,"published_at":"2026-09-22T16:18:06.963+00:00","url":"https://junglewise.ai/threats/cve-2026-88010-traefik-basicauth-singleflight-username-enumeration-via-timing"},{"cve":"CVE-2026-79913","cvss":6.5,"epss":0.004,"slug":"cve-2026-79913-cloudreve-ssrf-guard-bypass-via-ipv6-transition-wrappers","title":"Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in","severity":"medium","exploited":false,"published_at":"2026-09-22T16:17:57.033+00:00","url":"https://junglewise.ai/threats/cve-2026-79913-cloudreve-ssrf-guard-bypass-via-ipv6-transition-wrappers"},{"cve":"CVE-2026-77637","cvss":3.8,"epss":0.0033,"slug":"cve-2026-77637-cloudreve-privilege-scope-bypass-in-admin-api-endpoints","title":"Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET(\"wopi\") and tool.POST(\"mail\") in routers/router.go","severity":"low","exploited":false,"published_at":"2026-09-22T16:17:55.99+00:00","url":"https://junglewise.ai/threats/cve-2026-77637-cloudreve-privilege-scope-bypass-in-admin-api-endpoints"},{"cve":"CVE-2026-77633","cvss":7.1,"epss":0.0037,"slug":"cve-2026-77633-cloudreve-toctou-race-in-storage-quota-check-and-charge","title":"Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a","severity":"high","exploited":false,"published_at":"2026-09-22T16:17:55.817+00:00","url":"https://junglewise.ai/threats/cve-2026-77633-cloudreve-toctou-race-in-storage-quota-check-and-charge"},{"cvss":4.3,"slug":"falco-k8saudit-detection-bypass-for-privileged-init-and-ephemeral-7788502d","title":"Falco k8saudit detection bypass for privileged init and ephemeral containers","severity":"medium","exploited":false,"published_at":"2026-09-21T21:43:52+00:00","url":"https://junglewise.ai/threats/falco-k8saudit-detection-bypass-for-privileged-init-and-ephemeral-7788502d"},{"cvss":3.1,"slug":"k8saudit-shipped-rules-do-not-detect-privileged-sensitive-settings-on-640b2c3d","title":"k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers","severity":"low","exploited":false,"published_at":"2026-09-21T21:43:52+00:00","url":"https://junglewise.ai/threats/k8saudit-shipped-rules-do-not-detect-privileged-sensitive-settings-on-640b2c3d"}],"vendor":{"hub":true,"name":"Go","slug":"go","homepage":"https://go.dev/","ecosystem":"Go","description":"An open-source programming language supported by Google.","url":"https://junglewise.ai/threats/vendors/go"},"weekly":[{"week":"2026-06-29","critical":11,"exploited":0,"vulnerabilities":67},{"week":"2026-07-06","critical":5,"exploited":0,"vulnerabilities":95},{"week":"2026-07-13","critical":2,"exploited":0,"vulnerabilities":43},{"week":"2026-07-20","critical":5,"exploited":0,"vulnerabilities":109},{"week":"2026-07-27","critical":6,"exploited":0,"vulnerabilities":53},{"week":"2026-08-03","critical":3,"exploited":0,"vulnerabilities":34},{"week":"2026-08-10","critical":6,"exploited":0,"vulnerabilities":69},{"week":"2026-08-17","critical":10,"exploited":0,"vulnerabilities":81},{"week":"2026-08-24","critical":5,"exploited":1,"vulnerabilities":66},{"week":"2026-08-31","critical":7,"exploited":0,"vulnerabilities":58},{"week":"2026-09-07","critical":5,"exploited":0,"vulnerabilities":37},{"week":"2026-09-14","critical":6,"exploited":0,"vulnerabilities":96},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":39}],"most_severe":[{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"cve":"CVE-2020-0601","cvss":8.1,"epss":0.8944,"slug":"cve-2020-0601-microsoft-windows-cryptoapi-spoofing-vulnerability","title":"GO-2022-0535 - Certificate validation bypass on Windows in crypto/x509","severity":"critical","exploited":true,"published_at":"2022-08-01T22:21:17+00:00","url":"https://junglewise.ai/threats/cve-2020-0601-microsoft-windows-cryptoapi-spoofing-vulnerability"},{"cve":"CVE-2025-8110","cvss":4,"epss":0.852,"slug":"cve-2025-8110-gogs-path-traversal-and-code-execution-in-putcontents-api","title":"GO-2025-4225 - Gogs vulnerable to a bypass of in gogs.io/gogs","severity":"critical","exploited":true,"published_at":"2025-12-15T20:15:46+00:00","url":"https://junglewise.ai/threats/cve-2025-8110-gogs-path-traversal-and-code-execution-in-putcontents-api"},{"cve":"CVE-2026-33634","cvss":4,"epss":0.0168,"slug":"cve-2026-33634-aqua-security-trivy-supply-chain-compromise-via-malicious-code","title":"GO-2026-4919 - Trivy ecosystem supply chain was briefly compromised in github.com/aquasecurity/trivy","severity":"critical","exploited":true,"published_at":"2026-04-01T16:33:18+00:00","url":"https://junglewise.ai/threats/cve-2026-33634-aqua-security-trivy-supply-chain-compromise-via-malicious-code"},{"cve":"CVE-2025-24016","cvss":3.1,"epss":0.9384,"slug":"cve-2025-24016-wazuh-server-remote-code-execution-via-unsafe-deserialization","title":"GO-2025-3459 - Remote code execution in Wazuh server in github.com/wazuh/wazuh","severity":"critical","exploited":true,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-24016-wazuh-server-remote-code-execution-via-unsafe-deserialization"},{"cve":"CVE-2023-28434","cvss":3.1,"epss":0.0792,"slug":"cve-2023-28434-minio-security-feature-bypass-vulnerability","title":"Privilege Escalation on Linux/MacOS","severity":"critical","exploited":true,"published_at":"2023-09-05T15:45:10+00:00","url":"https://junglewise.ai/threats/cve-2023-28434-minio-security-feature-bypass-vulnerability"},{"cve":"CVE-2026-69084","cvss":10,"epss":0.0157,"slug":"cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock","title":"SiYuan arbitrary SQL execution via searchEmbedBlock","severity":"critical","exploited":false,"published_at":"2026-09-03T20:19:22+00:00","url":"https://junglewise.ai/threats/cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock"},{"cve":"CVE-2026-45087","cvss":10,"epss":0.0139,"slug":"cve-2026-45087-hahwul-dalfox-unauthenticated-rce-in-rest-api-server-mode","title":"hahwul Dalfox unauthenticated RCE in REST API server mode","severity":"critical","exploited":false,"published_at":"2026-05-27T18:16:24.567+00:00","url":"https://junglewise.ai/threats/cve-2026-45087-hahwul-dalfox-unauthenticated-rce-in-rest-api-server-mode"},{"cve":"CVE-2026-52813","cvss":10,"epss":0.0111,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-40281","cvss":10,"epss":0.0066,"slug":"cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint","title":"Gotenberg argument injection in metadata write endpoint","severity":"critical","exploited":false,"published_at":"2026-05-06T21:16:01.353+00:00","url":"https://junglewise.ai/threats/cve-2026-40281-gotenberg-argument-injection-in-metadata-write-endpoint"}],"generated_at":"2026-09-26T18:07:00.158435+00:00","technologies":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"},{"name":"github.com/juev/nebula-mesh (Go)","slug":"github-com-juev-nebula-mesh","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/github-com-juev-nebula-mesh"},{"name":"github.com/casdoor/casdoor (Go)","slug":"github-com-casdoor-casdoor","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/github-com-casdoor-casdoor"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"},{"name":"go.opentelemetry.io/obi (Go)","slug":"go-opentelemetry-io-obi","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/go-opentelemetry-io-obi"},{"name":"golang.org/x/crypto/ssh (Go)","slug":"golang-org-x-crypto-ssh","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/golang-org-x-crypto-ssh"},{"name":"github.com/axllent/mailpit (Go)","slug":"github-com-axllent-mailpit","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-axllent-mailpit"},{"name":"github.com/lxc/incus/v7/cmd/incusd (Go)","slug":"github-com-lxc-incus-v7-cmd-incusd","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-lxc-incus-v7-cmd-incusd"},{"name":"github.com/patrickhener/goshs/v2 (Go)","slug":"github-com-patrickhener-goshs-v2","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-patrickhener-goshs-v2"},{"name":"github.com/rabbitmq/amqp091-go (Go)","slug":"github-com-rabbitmq-amqp091-go","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-rabbitmq-amqp091-go"},{"name":"github.com/zitadel/zitadel (Go)","slug":"github-com-zitadel-zitadel","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-zitadel-zitadel"},{"name":"gitea.dev (Go)","slug":"gitea-dev","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/gitea-dev"},{"name":"github.com/0xJacky/Nginx-UI (Go)","slug":"github-com-0xjacky-nginx-ui","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-0xjacky-nginx-ui"},{"name":"github.com/cloudreve/Cloudreve/v3 (Go)","slug":"github-com-cloudreve-cloudreve-v3","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v3"},{"name":"github.com/free5gc/udr (Go)","slug":"github-com-free5gc-udr","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-udr"},{"name":"github.com/kyverno/kyverno (Go)","slug":"github-com-kyverno-kyverno","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-kyverno-kyverno"},{"name":"github.com/omec-project/amf (Go)","slug":"github-com-omec-project-amf","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-omec-project-amf"},{"name":"github.com/patrickhener/goshs (Go)","slug":"github-com-patrickhener-goshs","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-patrickhener-goshs"},{"name":"github.com/QuantumNous/new-api (Go)","slug":"github-com-quantumnous-new-api","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/github-com-quantumnous-new-api"},{"name":"github.com/lin-snow/ech0 (Go)","slug":"github-com-lin-snow-ech0","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/github-com-lin-snow-ech0"},{"name":"github.com/openbao/openbao (Go)","slug":"github-com-openbao-openbao","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/github-com-openbao-openbao"},{"name":"github.com/projectcapsule/capsule (Go)","slug":"github-com-projectcapsule-capsule","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/github-com-projectcapsule-capsule"},{"name":"goshs.de/goshs/v2 (Go)","slug":"goshs-de-goshs-v2","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/goshs-de-goshs-v2"},{"name":"github.com/apache/incubator-answer (Go)","slug":"github-com-apache-incubator-answer","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-apache-incubator-answer"},{"name":"github.com/argoproj/argo-workflows/v4 (Go)","slug":"github-com-argoproj-argo-workflows-v4","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-argoproj-argo-workflows-v4"},{"name":"github.com/caddyserver/caddy/v2 (Go)","slug":"github-com-caddyserver-caddy-v2","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-caddyserver-caddy-v2"},{"name":"github.com/enchant97/note-mark/backend (Go)","slug":"github-com-enchant97-note-mark-backend","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-enchant97-note-mark-backend"},{"name":"github.com/forgekeep/nebula-mesh (Go)","slug":"github-com-forgekeep-nebula-mesh","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-forgekeep-nebula-mesh"},{"name":"github.com/free5gc/nef (Go)","slug":"github-com-free5gc-nef","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-nef"},{"name":"github.com/getarcaneapp/arcane/backend (Go)","slug":"github-com-getarcaneapp-arcane-backend","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-getarcaneapp-arcane-backend"},{"name":"github.com/go-git/go-git/v5 (Go)","slug":"github-com-go-git-go-git-v5","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-go-git-go-git-v5"},{"name":"github.com/go-git/go-git/v6 (Go)","slug":"github-com-go-git-go-git-v6","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-go-git-go-git-v6"},{"name":"github.com/gohugoio/hugo (Go)","slug":"github-com-gohugoio-hugo","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-gohugoio-hugo"},{"name":"github.com/projectdiscovery/nuclei/v3 (Go)","slug":"github-com-projectdiscovery-nuclei-v3","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-projectdiscovery-nuclei-v3"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/xyproto/algernon (Go)","slug":"github-com-xyproto-algernon","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/github-com-xyproto-algernon"},{"name":"oras.land/oras-go/v2 (Go)","slug":"oras-land-oras-go-v2","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/oras-land-oras-go-v2"},{"name":"github.com/filebrowser/filebrowser (Go)","slug":"github-com-filebrowser-filebrowser","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser"},{"name":"github.com/googleapis/mcp-toolbox (Go)","slug":"github-com-googleapis-mcp-toolbox","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-googleapis-mcp-toolbox"},{"name":"github.com/OliveTin/OliveTin (Go)","slug":"github-com-olivetin-olivetin","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-olivetin-olivetin"},{"name":"github.com/openfga/openfga (Go)","slug":"github-com-openfga-openfga","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-openfga-openfga"},{"name":"github.com/seaweedfs/seaweedfs (Go)","slug":"github-com-seaweedfs-seaweedfs","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-seaweedfs-seaweedfs"},{"name":"github.com/authzed/spicedb (Go)","slug":"github-com-authzed-spicedb","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-authzed-spicedb"},{"name":"github.com/containers/podman/v5 (Go)","slug":"github-com-containers-podman-v5","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-containers-podman-v5"},{"name":"github.com/gtsteffaniak/filebrowser/backend (Go)","slug":"github-com-gtsteffaniak-filebrowser-backend","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-gtsteffaniak-filebrowser-backend"},{"name":"github.com/hatchet-dev/hatchet (Go)","slug":"github-com-hatchet-dev-hatchet","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-hatchet-dev-hatchet"},{"name":"github.com/juju/juju (Go)","slug":"github-com-juju-juju","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-juju-juju"},{"name":"github.com/modelcontextprotocol/registry (Go)","slug":"github-com-modelcontextprotocol-registry","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-modelcontextprotocol-registry"},{"name":"github.com/oauth2-proxy/oauth2-proxy/v7 (Go)","slug":"github-com-oauth2-proxy-oauth2-proxy-v7","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-oauth2-proxy-oauth2-proxy-v7"},{"name":"github.com/openziti/zrok (Go)","slug":"github-com-openziti-zrok","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-openziti-zrok"},{"name":"github.com/openziti/zrok/v2 (Go)","slug":"github-com-openziti-zrok-v2","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-openziti-zrok-v2"},{"name":"github.com/pterodactyl/wings (Go)","slug":"github-com-pterodactyl-wings","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-pterodactyl-wings"},{"name":"github.com/tektoncd/pipeline (Go)","slug":"github-com-tektoncd-pipeline","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-tektoncd-pipeline"},{"name":"github.com/tinfoil-factory/netfoil (Go)","slug":"github-com-tinfoil-factory-netfoil","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-tinfoil-factory-netfoil"},{"name":"github.com/zalando/skipper (Go)","slug":"github-com-zalando-skipper","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/github-com-zalando-skipper"},{"name":"chainguard.dev/apko (Go)","slug":"chainguard-dev-apko","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/chainguard-dev-apko"},{"name":"crypto (Go)","slug":"crypto","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/crypto"},{"name":"github.com/amir20/dozzle (Go)","slug":"github-com-amir20-dozzle","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-amir20-dozzle"},{"name":"github.com/argoproj/argo-workflows/v3 (Go)","slug":"github-com-argoproj-argo-workflows-v3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-argoproj-argo-workflows-v3"},{"name":"github.com/canonical/lxd (Go)","slug":"github-com-canonical-lxd","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-canonical-lxd"},{"name":"github.com/containers/podman/v4 (Go)","slug":"github-com-containers-podman-v4","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-containers-podman-v4"},{"name":"github.com/coredns/coredns (Go)","slug":"github-com-coredns-coredns","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-coredns-coredns"},{"name":"github.com/dadrus/heimdall (Go)","slug":"github-com-dadrus-heimdall","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-dadrus-heimdall"},{"name":"github.com/daytonaio/daytona (Go)","slug":"github-com-daytonaio-daytona","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-daytonaio-daytona"},{"name":"github.com/docker/docker (Go)","slug":"github-com-docker-docker","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-docker-docker"},{"name":"github.com/free5gc/pcf (Go)","slug":"github-com-free5gc-pcf","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-pcf"},{"name":"github.com/getkin/kin-openapi (Go)","slug":"github-com-getkin-kin-openapi","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-getkin-kin-openapi"},{"name":"github.com/hahwul/dalfox/v2 (Go)","slug":"github-com-hahwul-dalfox-v2","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-hahwul-dalfox-v2"},{"name":"github.com/hashicorp/vault (Go)","slug":"github-com-hashicorp-vault","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault"},{"name":"github.com/julien040/anyquery (Go)","slug":"github-com-julien040-anyquery","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-julien040-anyquery"},{"name":"github.com/kubev2v/migration-planner (Go)","slug":"github-com-kubev2v-migration-planner","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-kubev2v-migration-planner"},{"name":"github.com/moby/moby (Go)","slug":"github-com-moby-moby","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-moby-moby"},{"name":"github.com/moby/moby/v2 (Go)","slug":"github-com-moby-moby-v2","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-moby-moby-v2"},{"name":"github.com/neuvector/neuvector (Go)","slug":"github-com-neuvector-neuvector","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-neuvector-neuvector"},{"name":"github.com/nhost/nhost (Go)","slug":"github-com-nhost-nhost","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-nhost-nhost"},{"name":"github.com/nuclio/nuclio (Go)","slug":"github-com-nuclio-nuclio","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-nuclio-nuclio"},{"name":"github.com/obot-platform/obot (Go)","slug":"github-com-obot-platform-obot","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-obot-platform-obot"},{"name":"github.com/oxia-db/oxia (Go)","slug":"github-com-oxia-db-oxia","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-oxia-db-oxia"},{"name":"github.com/shellhub-io/shellhub (Go)","slug":"github-com-shellhub-io-shellhub","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-shellhub-io-shellhub"},{"name":"github.com/tomwright/dasel/v3 (Go)","slug":"github-com-tomwright-dasel-v3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-tomwright-dasel-v3"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"gitlab.com/uniget-org/cli (Go)","slug":"gitlab-com-uniget-org-cli","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gitlab-com-uniget-org-cli"},{"name":"golang.org/x/crypto/ssh/agent (Go)","slug":"golang-org-x-crypto-ssh-agent","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/golang-org-x-crypto-ssh-agent"},{"name":"goshs.de/goshs (Go)","slug":"goshs-de-goshs","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/goshs-de-goshs"},{"name":"k8s.io/kubernetes (Go)","slug":"k8s-io-kubernetes","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/k8s-io-kubernetes"},{"name":"www.velocidex.com/golang/velociraptor (Go)","slug":"www-velocidex-com-golang-velociraptor","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/www-velocidex-com-golang-velociraptor"},{"name":"github.com/anchore/quill (Go)","slug":"github-com-anchore-quill","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-anchore-quill"},{"name":"github.com/aquasecurity/trivy (Go)","slug":"github-com-aquasecurity-trivy","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-aquasecurity-trivy"},{"name":"github.com/basekick-labs/arc (Go)","slug":"github-com-basekick-labs-arc","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-basekick-labs-arc"},{"name":"github.com/caddyserver/caddy (Go)","slug":"github-com-caddyserver-caddy","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-caddyserver-caddy"},{"name":"github.com/dgraph-io/dgraph/v25 (Go)","slug":"github-com-dgraph-io-dgraph-v25","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-dgraph-io-dgraph-v25"},{"name":"github.com/ellanetworks/core (Go)","slug":"github-com-ellanetworks-core","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-ellanetworks-core"},{"name":"github.com/free5gc/amf (Go)","slug":"github-com-free5gc-amf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-amf"},{"name":"github.com/free5gc/ausf (Go)","slug":"github-com-free5gc-ausf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-ausf"},{"name":"github.com/free5gc/smf (Go)","slug":"github-com-free5gc-smf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-free5gc-smf"},{"name":"github.com/go-chi/chi/v5/middleware (Go)","slug":"github-com-go-chi-chi-v5-middleware","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-go-chi-chi-v5-middleware"},{"name":"github.com/gofiber/fiber/v3 (Go)","slug":"github-com-gofiber-fiber-v3","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-gofiber-fiber-v3"},{"name":"github.com/grafana/grafana (Go)","slug":"github-com-grafana-grafana","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-grafana-grafana"},{"name":"github.com/gtsteffaniak/filebrowser (Go)","slug":"github-com-gtsteffaniak-filebrowser","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-gtsteffaniak-filebrowser"},{"name":"github.com/inspektor-gadget/inspektor-gadget (Go)","slug":"github-com-inspektor-gadget-inspektor-gadget","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-inspektor-gadget-inspektor-gadget"},{"name":"github.com/iskorotkov/avro/v2 (Go)","slug":"github-com-iskorotkov-avro-v2","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-iskorotkov-avro-v2"},{"name":"github.com/jackc/pgx/v5 (Go)","slug":"github-com-jackc-pgx-v5","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-jackc-pgx-v5"},{"name":"github.com/kata-containers/kata-containers (Go)","slug":"github-com-kata-containers-kata-containers","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-kata-containers-kata-containers"},{"name":"github.com/lf-edge/ekuiper/v2 (Go)","slug":"github-com-lf-edge-ekuiper-v2","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-lf-edge-ekuiper-v2"},{"name":"github.com/lucasdillmann/nginx-ignition (Go)","slug":"github-com-lucasdillmann-nginx-ignition","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-lucasdillmann-nginx-ignition"},{"name":"github.com/moby/buildkit (Go)","slug":"github-com-moby-buildkit","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-moby-buildkit"},{"name":"github.com/ollama/ollama (Go)","slug":"github-com-ollama-ollama","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-ollama-ollama"},{"name":"github.com/openclaw/crabbox (Go)","slug":"github-com-openclaw-crabbox","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-openclaw-crabbox"},{"name":"github.com/OpenListTeam/OpenList/v4 (Go)","slug":"github-com-openlistteam-openlist-v4","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-openlistteam-openlist-v4"},{"name":"github.com/osrg/gobgp/v4 (Go)","slug":"github-com-osrg-gobgp-v4","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-osrg-gobgp-v4"},{"name":"github.com/perses/perses (Go)","slug":"github-com-perses-perses","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-perses-perses"},{"name":"github.com/pocket-id/pocket-id/backend (Go)","slug":"github-com-pocket-id-pocket-id-backend","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-pocket-id-pocket-id-backend"},{"name":"github.com/semaphoreui/semaphore (Go)","slug":"github-com-semaphoreui-semaphore","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-semaphoreui-semaphore"},{"name":"github.com/sonirico/mcp-shell (Go)","slug":"github-com-sonirico-mcp-shell","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-sonirico-mcp-shell"},{"name":"github.com/stacklok/toolhive (Go)","slug":"github-com-stacklok-toolhive","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-stacklok-toolhive"},{"name":"github.com/tilt-dev/tilt (Go)","slug":"github-com-tilt-dev-tilt","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-tilt-dev-tilt"},{"name":"github.com/xuri/excelize/v2 (Go)","slug":"github-com-xuri-excelize-v2","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-xuri-excelize-v2"},{"name":"go (Go)","slug":"go","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/go"},{"name":"go.senan.xyz/gonic (Go)","slug":"go-senan-xyz-gonic","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/go-senan-xyz-gonic"},{"name":"google.golang.org/grpc (Go)","slug":"google-golang-org-grpc","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/google-golang-org-grpc"},{"name":"helm.sh/helm/v4 (Go)","slug":"helm-sh-helm-v4","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/helm-sh-helm-v4"}]}