Package impact

golang Go / toolchain

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-27144 high 8.0 1mo ago Important: golang security update
CVE-2026-27140 high 8.0 1mo ago Important: golang security update
CVE-2026-27143 high 8.0 1mo ago Important: golang security update
CVE-2025-61731 high 8.0 2mo ago Important: golang security update
CVE-2025-61732 high 8.0 3mo ago Important: golang security update
CVE-2025-4674 high 8.0 10mo ago Important: golang security update
CVE-2018-6574 high 8.0 4y ago Remote command execution via "go get" command with cgo in cmd/go
CVE-2018-16873 high 8.0 4y ago Remote command execution via "go get" with "-u" flag in cmd/go
CVE-2018-16874 high 8.0 4y ago Directory traversal via "go get" command in cmd/go
CVE-2026-42501 high 7.5 7.5 22d ago A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module pr…
CVE-2026-39817 medium 5.9 5.9 22d ago The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" su…
CVE-2023-45285 medium 5.5 2y ago Moderate: golang security update
CVE-2023-39323 medium 5.5 3y ago RHBA-2023:6928: go-toolset:rhel8 bug fix and enhancement update (Moderate)
CVE-2022-23773 medium 5.5 4y ago Moderate: go-toolset:rhel8 security and bug fix update
CVE-2020-28367 medium 5.5 4y ago RHSA-2020:5493: go-toolset:rhel8 security update (Moderate)
CVE-2020-28366 medium 5.5 4y ago RHSA-2020:5493: go-toolset:rhel8 security update (Moderate)
CVE-2021-38297 medium 5.5 4y ago Moderate: go-toolset:rhel8 security and bug fix update
CVE-2021-3115 medium 5.5 5y ago RHSA-2021:1746: go-toolset:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2026-39819 medium 5.3 5.3 22d ago The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one…