Go
3,249 CVEs tracked since 2014. Since Sep 2021, 6 of them reached CISA KEV.
Go CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 16 | 0 |
| 2021-10 | 15 | 1 |
| 2021-11 | 21 | 0 |
| 2021-12 | 13 | 1 |
| 2022-01 | 10 | 0 |
| 2022-02 | 47 | 0 |
| 2022-03 | 36 | 0 |
| 2022-04 | 24 | 0 |
| 2022-05 | 44 | 0 |
| 2022-06 | 29 | 0 |
| 2022-07 | 25 | 0 |
| 2022-08 | 15 | 0 |
| 2022-09 | 47 | 0 |
| 2022-10 | 32 | 0 |
| 2022-11 | 34 | 0 |
| 2022-12 | 126 | 0 |
| 2023-01 | 33 | 0 |
| 2023-02 | 44 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 26 | 0 |
| 2023-05 | 35 | 0 |
| 2023-06 | 42 | 0 |
| 2023-07 | 30 | 0 |
| 2023-08 | 37 | 0 |
| 2023-09 | 64 | 1 |
| 2023-10 | 44 | 1 |
| 2023-11 | 37 | 0 |
| 2023-12 | 32 | 0 |
| 2024-01 | 46 | 0 |
| 2024-02 | 52 | 0 |
| 2024-03 | 53 | 0 |
| 2024-04 | 64 | 0 |
| 2024-05 | 45 | 0 |
| 2024-06 | 33 | 0 |
| 2024-07 | 49 | 0 |
| 2024-08 | 62 | 0 |
| 2024-09 | 40 | 0 |
| 2024-10 | 65 | 0 |
| 2024-11 | 42 | 0 |
| 2024-12 | 39 | 0 |
| 2025-01 | 49 | 0 |
| 2025-02 | 35 | 1 |
| 2025-03 | 60 | 0 |
| 2025-04 | 56 | 0 |
| 2025-05 | 50 | 0 |
| 2025-06 | 50 | 0 |
| 2025-07 | 34 | 0 |
| 2025-08 | 75 | 0 |
| 2025-09 | 55 | 0 |
| 2025-10 | 60 | 0 |
| 2025-11 | 70 | 0 |
| 2025-12 | 83 | 1 |
| 2026-01 | 85 | 0 |
| 2026-02 | 143 | 0 |
| 2026-03 | 139 | 0 |
| 2026-04 | 62 | 0 |
| 2026-05 | 41 | 0 |
| 2026-06 | 35 | 0 |
| 2026-07 | 31 | 0 |
| 2026-08 | 46 | 0 |
| 2026-09 | 13 | 0 |
Products
The products that kept showing up in Go's monthly top three, with their CVEs summed over those months.
- Github.com/mattermost/mattermost/server/v8149
- Github.com/usememos/memos54
- Github.com/siyuan-note/siyuan/kernel51
- Github.com/mattermost/mattermost-server47
- Github.com/rancher/rancher33
- Gogs.io/gogs27
- Github.com/mattermost/mattermost-server/v620
- Github.com/grafana/grafana17
- Github.com/lf-edge/eve14
- Github.com/lin-snow/ech014
Latest CVEs
The 15 most recently published vulnerabilities affecting Go.
- GHSA-jhjp-4c2q-xmx4k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers—
- GHSA-jgh3-fggc-mcpmObot: Server-Side Request Forgery via remote MCP server URL—
- GHSA-pr6h-vr44-xq8jObot: MCP Registry API readable without authentication—
- GHSA-xwmw-prc4-v3crObot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion—
- CVE-2026-78427Admission Control Bypass via Hardcoded Sidecar Image Exemption4.3
- CVE-2026-78425SAML Audience Confusion Allows Cross-SP Authentication—
- CVE-2026-78426Logout bypass via alternate JWT spelling3.7
- CVE-2026-78428Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently8.0
- GHSA-rf68-8gjr-36q7Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty—
- GHSA-hxjg-93wc-h8p8Komari: Management Interface CSRF—
- GHSA-57v5-wqx3-cgj4SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews—
- GHSA-7j72-f6wg-cxw6SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)—
- GHSA-gw25-m53r-qh88SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)—
- GHSA-99rq-75j6-5j9fSiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass—
- GHSA-mf7q-r4rv-jv94Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check—
The record
- Peak rank
- #3 in Feb 2026
- Busiest month shown
- Feb 2026, 143 CVEs
- Months with a KEV entry
- 6 since Sep 2021
- Monthly snapshots
- 106 since 2014