Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Golang

62 known vulnerabilities

11
CRITICAL
24
HIGH
24
MEDIUM
2
LOW

Top Products

go 38 crypto 13 net 6 tiff 2 image 2 http2 1
61 CVEs · Page 1/2
5.3
CVE-2026-42505

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of

7.8
CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina

7.5
CVE-2026-46604

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

7.5
CVE-2023-54365

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri

6.1
CVE-2026-42506

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged

6.1
CVE-2026-42502

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged

9.6
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For e

6.1
CVE-2026-27136

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged

6.1
CVE-2026-25681

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged

6.5
CVE-2026-25680

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

5.3
CVE-2026-46598

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when

7.5
CVE-2026-46597

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte

10.0
CVE-2026-46595

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal

9.1
CVE-2026-42508

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and

5.3
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c

9.1
CVE-2026-39834

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload

9.1
CVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf

9.1
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as [email protected] were not serializ

9.1
CVE-2026-39831

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did

9.1
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection

7.5
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive

6.3
CVE-2026-39828

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were

6.5
CVE-2026-39827

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr

7.5
CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa

7.5
CVE-2026-42499

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

7.5
CVE-2026-39836

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

6.1
CVE-2026-39826

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit

5.3
CVE-2026-39825

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi

6.1
CVE-2026-39823

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu

7.5
CVE-2026-39820

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion

5.3
CVE-2026-39819

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").

5.9
CVE-2026-39817

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa

7.5
CVE-2026-33814

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei

7.5
CVE-2026-33811

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a

7.5
CVE-2026-33813

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

6.1
CVE-2026-33812

Parsing a malicious font file can cause excessive memory allocation.

8.2
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w

6.1
CVE-2026-32289

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi

5.5
CVE-2026-32288

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb

7.5
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c

6.4
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope

7.5
CVE-2026-32281

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve

7.5
CVE-2026-32280

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert

7.1
CVE-2026-27144

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented

9.8
CVE-2026-27143

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp

8.8
CVE-2026-27140

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at

5.3
CVE-2026-33809

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess

6.1
CVE-2026-27142

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t

2.5
CVE-2026-27139

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou

5.9
CVE-2026-27138

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the

Frequently Asked Questions

How many CVEs affect Golang?

Golang has 62 CVE records in our database, including 11 critical and 25 high severity vulnerabilities.

What are the most severe Golang vulnerabilities?

Golang has 11 critical severity (CVSS 9.0+) and 25 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Golang vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Golang products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Golang Vulnerabilities

CyberStrike scans your infrastructure for Golang vulnerabilities and provides real-time remediation guidance.

Get Started