Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
- CVE-2026-53433, GHSA-mvmf-94v6-879g
- Affects: github.com/junegunn/fzf
- Published: Oct 01, 2026
- Unreviewed
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf
- CVE-2024-29296, GHSA-87x6-8m9v-g8c2
- Affects: github.com/portainer/portainer
- Published: Oct 01, 2026
- Unreviewed
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
- CVE-2026-81869, GHSA-p9f8-wvj8-2fg8
- Affects: go.opentelemetry.io/otel/sdk
- Published: Oct 01, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk
- CVE-2026-81872, GHSA-hjf4-fphr-2h65
- Affects: go.opentelemetry.io/otel/sdk/log
- Published: Oct 01, 2026
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log
- CVE-2026-53493, GHSA-pg57-6jwg-q645
- Affects: github.com/containerd/containerd, github.com/containerd/containerd/v2
- Published: Oct 01, 2026
- Unreviewed
Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.