Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
- CVE-2026-56668, GHSA-vrh8-c9cm-wh8v
- Affects: github.com/zitadel/zitadel
- Published: Sep 16, 2026
- Unreviewed
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel before v4.15.3.
- CVE-2026-76081, GHSA-v859-c572-qh5p
- Affects: github.com/zitadel/zitadel
- Published: Sep 16, 2026
- Unreviewed
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel before v4.16.0.
- CVE-2026-56666, GHSA-992q-9gwp-7r79
- Affects: github.com/zitadel/zitadel
- Published: Sep 16, 2026
- Unreviewed
ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel before v4.15.3.
- CVE-2026-56665, GHSA-v77h-2w3m-94hx
- Affects: github.com/zitadel/zitadel
- Published: Sep 16, 2026
- Unreviewed
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel before v3.4.12, from v4.0.0-rc.1 before v4.15.2.
- CVE-2026-88008, GHSA-w4v4-9rw7-5326
- Affects: github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more
- Published: Sep 16, 2026
- Unreviewed
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.