Direct Vulnerabilities

Known vulnerabilities in the go package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Allocation of Resources Without Limits or Throttling

<1.26.2-r0
  • M
Allocation of Resources Without Limits or Throttling

<1.26.2-r0
  • C
CVE-2026-27143

<1.26.2-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.25.2-r0
  • M
Cross-site Scripting (XSS)

<1.26.2-r0
  • L
CVE-2025-4674

<1.24.5-r0
  • L
CVE-2025-58186

<1.25.2-r0
  • L
CVE-2025-22874

<1.24.4-r0
  • L
CVE-2024-45341

<1.23.5-r0
  • M
Cross-site Scripting (XSS)

<1.21.1-r0
  • C
Arbitrary Code Injection

<1.21.1-r0
  • L
Direct Request ('Forced Browsing')

<1.25.8-r0
  • L
CVE-2024-45336

<1.23.5-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.20.3-r0
  • C
Arbitrary Code Injection

<1.20.3-r0
  • L
Improper Certificate Validation

<1.25.8-r0
  • C
Arbitrary Code Injection

<1.20.5-r0
  • H
Arbitrary Code Injection

<1.20.4-r0
  • L
Cross-site Scripting (XSS)

<1.26.3-r0
  • H
Arbitrary Code Injection

<1.9.4-r0
  • L
Improper Encoding or Escaping of Output

<1.26.3-r0
  • H
Double Free

<1.26.3-r0
  • L
CVE-2026-42501

<1.26.3-r0
  • L
Improper Certificate Validation

<1.25.8-r0
  • H
NULL Pointer Dereference

<1.26.3-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.26.3-r0
  • L
Information Exposure Through Log Files

<1.25.2-r0
  • H
Incorrect Authorization

<1.26.2-r0
  • L
CVE-2025-22870

<1.24.1-r0
  • L
CVE-2025-22866

<1.23.6-r0
  • L
Cross-site Scripting (XSS)

<1.25.8-r0
  • L
CVE-2025-61732

<1.25.7-r0
  • H
Improper Certificate Validation

<1.26.2-r0
  • L
CVE-2025-58183

<1.25.2-r0
  • L
CVE-2024-24788

<1.22.3-r0
  • M
Link Following

<1.26.2-r0
  • C
CVE-2025-68121

<1.25.7-r0
  • L
CVE-2023-45288

<1.22.2-r0
  • L
Improper Certificate Validation

<1.25.5-r0
  • L
CVE-2024-34156

<1.23.1-r0
  • H
Exposure of Resource to Wrong Sphere

<1.20.5-r0
  • L
CVE-2023-39324

<1.21.5-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.25.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.25.6-r0
  • L
CVE-2026-39825

<1.26.3-r0
  • L
CVE-2024-24791

<1.22.5-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.21.3-r0
  • M
Interpretation Conflict

<1.20.6-r0
  • L
CVE-2024-24785

<1.22.1-r0
  • M
Incorrect Calculation

<1.20.2-r0
  • L
Out-of-bounds Write

<1.25.6-r0
  • L
Algorithmic Complexity

<1.25.2-r0
  • L
Improper Certificate Validation

<1.25.5-r0
  • L
CVE-2025-22873

<1.24.3-r0
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.26.2-r0
  • M
CVE-2023-39326

<1.21.5-r0
  • L
CVE-2025-22871

<1.24.2-r0
  • L
CVE-2024-24783

<1.22.1-r0
  • H
CVE-2023-44487

<1.21.3-r0
  • L
Directory Traversal

<1.25.8-r0
  • H
Resource Exhaustion

<1.20.3-r0
  • L
CVE-2025-47906

<1.24.6-r0
  • H
Integer Overflow or Wraparound

<1.20.3-r0
  • L
Race Condition

<1.24.6-r0
  • H
CVE-2023-39323

<1.21.2-r0
  • L
CVE-2026-42499

<1.26.3-r0
  • M
Link Following

<1.26.3-r0
  • L
CVE-2025-61725

<1.25.2-r0
  • L
CVE-2025-47910

<1.25.1-r0
  • L
CVE-2024-34158

<1.23.1-r0
  • L
CVE-2025-47912

<1.25.2-r0
  • M
CVE-2024-24789

<1.22.4-r0
  • L
CVE-2024-34155

<1.23.1-r0
  • M
Resource Exhaustion

<1.20.7-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.25.2-r0
  • C
CVE-2024-24790

<1.22.4-r0
  • H
Arbitrary Code Injection

<1.20.4-r0
  • C
CVE-2023-24540

<1.20.4-r0
  • M
Allocation of Resources Without Limits or Throttling

<1.19.4-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.19.2-r0
  • L
CVE-2026-32280

<1.26.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.21.1-r0
  • M
Out-of-bounds Write

<1.26.3-r0
  • H
Improper Certificate Validation

<1.26.2-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.25.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.17.1-r0
  • L
CVE-2025-61730

<1.25.6-r0
  • C
Unchecked Return Value

<1.17.7-r0
  • M
Improper Resource Shutdown or Release

<1.17.6-r0
  • M
CVE-2020-29509

<1.17-r0
  • L
CVE-2025-4673

<1.24.4-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.26.3-r0
  • L
CVE-2023-45289

<1.22.1-r0
  • L
Improper Certificate Validation

<1.25.2-r0
  • M
Cross-site Scripting (XSS)

<1.21.1-r0
  • L
CVE-2025-61731

<1.25.6-r0
  • H
CVE-2023-39321

<1.21.1-r0
  • M
Race Condition

<1.14.5-r0
  • L
Link Following

<1.24.4-r0
  • L
CVE-2023-45290

<1.22.1-r0
  • C
Arbitrary Code Injection

<1.20.5-r0
  • C
Arbitrary Code Injection

<1.20.5-r0
  • H
CVE-2021-33198

<1.16.5-r0
  • H
Arbitrary Code Injection

<1.16.5-r0
  • H
Improper Certificate Validation

<1.13.7-r0
  • M
Race Condition

<1.16.7-r0
  • M
Improper Certificate Validation

<1.16.6-r0
  • H
Resource Exhaustion

<1.20.1-r0
  • M
Missing Authorization

<1.16.5-r0
  • H
HTTP Request Smuggling

<1.13.1-r0
  • H
Interpretation Conflict

<1.13.2-r0
  • L
CVE-2024-24784

<1.22.1-r0
  • M
Uncontrolled Recursion

<1.18.4-r0
  • M
HTTP Request Smuggling

<1.18.4-r0
  • H
Uncontrolled Recursion

<1.18.1-r0
  • H
Directory Traversal

<1.19.1-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • H
CVE-2022-27664

<1.19.1-r0
  • H
Resource Exhaustion

<1.17.6-r0
  • H
Out-of-Bounds

<1.17.3-r0
  • H
Uncontrolled Recursion

<1.17.8-r0
  • M
Uncontrolled Recursion

<1.16.4-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • M
CVE-2021-27919

<1.16.2-r0
  • C
Buffer Overflow

<1.17.2-r0
  • H
CVE-2022-41723

<1.20.1-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.20.1-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.15-r0
  • M
Cross-site Scripting (XSS)

<1.15.2-r0
  • H
HTTP Request Smuggling

<1.19.2-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • H
Interpretation Conflict

<1.17.7-r0
  • H
Integer Overflow or Wraparound

<1.17.7-r0
  • M
CVE-2020-29511

<1.17-r0
  • H
CVE-2022-41715

<1.19.2-r0
  • H
Arbitrary Code Injection

<1.15.7-r0
  • M
CVE-2022-32148

<1.18.4-r0
  • H
Arbitrary Argument Injection

<1.15.5-r0
  • C
CVE-2019-14809

<1.12.8-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.12.8-r0
  • H
CVE-2021-29923

<1.17-r0
  • H
CVE-2022-28327

<1.18.1-r0
  • H
CVE-2022-32189

<1.18.5-r0
  • M
Incorrect Calculation

<1.15.7-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.16.2-r0
  • H
Uncontrolled Recursion

<1.18.4-r0
  • H
Improper Certificate Validation

<1.15.5-r0
  • H
Resource Exhaustion

<1.12.8-r0
  • H
Arbitrary Code Injection

<1.15.5-r0
  • H
Improper Certificate Validation

<1.18.1-r0
  • H
Resource Exhaustion

<1.16.5-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.11.5-r0
  • H
Improper Input Validation

<1.17.3-r0