Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Go
Package ecosystem Go. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.
Totals
| CVEs all-time | CVEs YTD | Packages affected |
|---|---|---|
| 17 | 16 | 6 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▂▅█
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 1 · 2026-09 4 · 2026-10 8
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-43871 | 8.7 | 62.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt… |
| CVE-2026-48586 | 8.7 | 62.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-55969 | 8.7 | 62.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-93450 | 8.7 | 59.0 | — | go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal … |
| CVE-2026-77763 | 7.1 | 40.7 | — | JuiceFS Local Filestore Backend Joins Object Keys onto the Storage Root Without a Conta… |
| CVE-2026-92393 | 2.0 | 37.2 | — | Apache YuniKorn: Admission control bypass via workload UPDATE operation |
| CVE-2026-63772 | 8.7 | 34.8 | — | Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader… |
| CVE-2026-82458 | 8.7 | 34.8 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-83663 | 8.7 | 34.8 | — | Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that … |
| CVE-2026-94637 | 8.2 | 34.8 | — | Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame |
| CVE-2026-97146 | 4.8 | 28.3 | — | Apache YuniKorn: Admission control bypass via system label forgery |
| CVE-2026-102510 | 8.7 | 23.8 | — | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled … |
| CVE-2024-9355 | 6.5 | 20.6 | — | Golang-fips: golang fips zeroed buffer |
| CVE-2026-66055 | 8.2 | 16.6 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-78243 | 2.1 | 15.1 | — | Apache YuniKorn: LDAP Group provider panics on lowercase attribute name |
| CVE-2026-97736 | 5.4 | 10.0 | — | — |
| CVE-2026-102511 | 8.5 | 6.7 | — | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed r… |
Most-affected packages
| Package | CVEs |
|---|---|
| github.com/apache/thrift | 8 |
| github.com/apache/yunikorn-k8shim | 3 |
| github.com/apache/plc4x/plc4go | 2 |
| github.com/golang-fips/openssl | 1 |
| github.com/juicedata/juicefs | 1 |
| github.com/tinyauthapp/tinyauth | 1 |