Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Golang

62 known vulnerabilities

11
CRITICAL
24
HIGH
24
MEDIUM
2
LOW

Top Products

go 38 crypto 13 net 6 tiff 2 image 2 http2 1
61 CVEs · Page 2/2
7.5
CVE-2026-27137

When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar

7.5
CVE-2026-25679

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

9.4
CVE-2025-66630

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c

10.0
CVE-2025-68121

During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th

8.6
CVE-2025-61732

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

3.8
CVE-2025-22873

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp

7.0
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria

7.8
CVE-2025-61731

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of

5.3
CVE-2025-61730

During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc

6.5
CVE-2025-61728

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open

7.5
CVE-2025-61726

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p

Frequently Asked Questions

How many CVEs affect Golang?

Golang has 62 CVE records in our database, including 11 critical and 25 high severity vulnerabilities.

What are the most severe Golang vulnerabilities?

Golang has 11 critical severity (CVSS 9.0+) and 25 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Golang vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Golang products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Golang Vulnerabilities

CyberStrike scans your infrastructure for Golang vulnerabilities and provides real-time remediation guidance.

Get Started