CVE Tools

Go

3,249 CVEs tracked since 2014. Since Sep 2021, 6 of them reached CISA KEV.

Go CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Go CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09160
2021-10151
2021-11210
2021-12131
2022-01100
2022-02470
2022-03360
2022-04240
2022-05440
2022-06290
2022-07250
2022-08150
2022-09470
2022-10320
2022-11340
2022-121260
2023-01330
2023-02440
2023-03null or fewer
2023-04260
2023-05350
2023-06420
2023-07300
2023-08370
2023-09641
2023-10441
2023-11370
2023-12320
2024-01460
2024-02520
2024-03530
2024-04640
2024-05450
2024-06330
2024-07490
2024-08620
2024-09400
2024-10650
2024-11420
2024-12390
2025-01490
2025-02351
2025-03600
2025-04560
2025-05500
2025-06500
2025-07340
2025-08750
2025-09550
2025-10600
2025-11700
2025-12831
2026-01850
2026-021430
2026-031390
2026-04620
2026-05410
2026-06350
2026-07310
2026-08460
2026-09130

Products

The products that kept showing up in Go's monthly top three, with their CVEs summed over those months.

  1. Github.com/mattermost/mattermost/server/v814920 months
  2. Github.com/usememos/memos542 months
  3. Github.com/siyuan-note/siyuan/kernel515 months
  4. Github.com/mattermost/mattermost-server477 months
  5. Github.com/rancher/rancher337 months
  6. Gogs.io/gogs274 months
  7. Github.com/mattermost/mattermost-server/v6203 months
  8. Github.com/grafana/grafana176 months
  9. Github.com/lf-edge/eve141 month
  10. Github.com/lin-snow/ech0142 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Go.

  1. GHSA-jhjp-4c2q-xmx4k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers—
  2. GHSA-jgh3-fggc-mcpmObot: Server-Side Request Forgery via remote MCP server URL—
  3. GHSA-pr6h-vr44-xq8jObot: MCP Registry API readable without authentication—
  4. GHSA-xwmw-prc4-v3crObot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion—
  5. CVE-2026-78427Admission Control Bypass via Hardcoded Sidecar Image Exemption4.3
  6. CVE-2026-78425SAML Audience Confusion Allows Cross-SP Authentication—
  7. CVE-2026-78426Logout bypass via alternate JWT spelling3.7
  8. CVE-2026-78428Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently8.0
  9. GHSA-rf68-8gjr-36q7Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty—
  10. GHSA-hxjg-93wc-h8p8Komari: Management Interface CSRF—
  11. GHSA-57v5-wqx3-cgj4SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews—
  12. GHSA-7j72-f6wg-cxw6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)—
  13. GHSA-gw25-m53r-qh88SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)—
  14. GHSA-99rq-75j6-5j9fSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass—
  15. GHSA-mf7q-r4rv-jv94Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check—

The record

Peak rank
#3 in Feb 2026
Busiest month shown
Feb 2026, 143 CVEs
Months with a KEV entry
6 since Sep 2021
Monthly snapshots
106 since 2014
Go's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store