CVE Tools

Go-standard-library

61 CVEs tracked since 2022. Since Aug 2022, none of them reached CISA KEV.

Go-standard-library CVEs per month

Aug 2022 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Go-standard-library CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-08130
2022-09null or fewer
2022-1030
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-0240
2023-03null or fewer
2023-0440
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-0940
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0350
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-0930
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10100
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0470
2026-0580

Products

The products that kept showing up in Go-standard-library's monthly top three, with their CVEs summed over those months.

  1. Crypto/x50963 months
  2. Html/template64 months
  3. Crypto/tls54 months
  4. Archive/tar33 months
  5. Net/http32 months
  6. Net/mail32 months
  7. Encoding/xml21 month
  8. Mime/multipart22 months
  9. Net21 month
  10. Net/textproto21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Go-standard-library.

  1. CVE-2026-56862Limit handshake messages we are willing to accept post-handshake in crypto/tls7.5
  2. CVE-2026-56858Fix Javascript regexp context tracking in html/template6.1
  3. CVE-2026-56853Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http7.5
  4. CVE-2026-56860Avoid quadratic complexity in resolvePath in net/url5.9
  5. CVE-2026-56859Add recursion depth guard during decode in encoding/xml7.5
  6. CVE-2026-33818Enforce maximum recursion depth in encoding/asn17.5
  7. CVE-2026-46600Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage7.5
  8. CVE-2026-42505Invoking Encrypted Client Hello privacy leak in crypto/tls5.3
  9. CVE-2026-39822Root escape via symlink plus trailing slash in os7.8
  10. CVE-2026-42507Arbitrary inputs are included in errors without any escaping in net/textproto5.3
  11. CVE-2026-42504Quadratic complexity in WordDecoder.DecodeHeader in mime7.5
  12. CVE-2026-27145Inefficient candidate hostname parsing in crypto/x5096.5
  13. CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna9.6
  14. CVE-2026-39820Quadratic string concatentation in consumeComment in net/mail7.5
  15. CVE-2026-39823Bypass of meta content URL escaping causes XSS in html/template6.1

The record

Peak rank
#54 in Aug 2022
Busiest month shown
Aug 2022, 13 CVEs
Months with a KEV entry
0 since Aug 2022
Monthly snapshots
10 since 2022
Go-standard-library's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store