Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
GO-2026-4548
- GHSA-2phg-qgmm-r638
- Affects: github.com/bishopfox/sliver
- Published: Feb 25, 2026
Sliver has Potential Zip Bomb Denial of Service in GzipEncoder in github.com/bishopfox/sliver
GO-2026-4547
- CVE-2026-27626, GHSA-49gm-hh7w-wfvf
- Affects: github.com/OliveTin/OliveTin
- Published: Feb 25, 2026
OliveTin: OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checks in github.com/OliveTin/OliveTin
GO-2026-4546
- CVE-2026-27611, GHSA-8vrh-3pm2-v4v6
- Affects: github.com/gtsteffaniak/filebrowser/backend
- Published: Feb 25, 2026
FileBrowser Quantum: Password Protection Not Enforced on Shared File Links in github.com/gtsteffaniak/filebrowser/backend
GO-2026-4545
- CVE-2025-50180, GHSA-3c9r-837r-qqm4
- Affects: github.com/esm-dev/esm.sh
- Published: Feb 25, 2026
esm.sh is vulnerable to full-response SSRF in github.com/esm-dev/esm.sh
GO-2026-4542
- CVE-2026-27598, GHSA-6v48-fcq6-ff23
- Affects: github.com/dagu-org/dagu
- Published: Feb 25, 2026
Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory in github.com/dagu-org/dagu
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.