Golang
62 known vulnerabilities
Top Products
When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of
During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instanc
archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is open
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p
Frequently Asked Questions
How many CVEs affect Golang?
Golang has 62 CVE records in our database, including 11 critical and 25 high severity vulnerabilities.
What are the most severe Golang vulnerabilities?
Golang has 11 critical severity (CVSS 9.0+) and 25 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Golang vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Golang products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Golang Vulnerabilities
CyberStrike scans your infrastructure for Golang vulnerabilities and provides real-time remediation guidance.
Get Started