boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Go

Package ecosystem Go. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDPackages affected
17166

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▂▅█

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 1 · 2026-09 4 · 2026-10 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-438718.762.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-485868.762.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-559698.762.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-934508.759.0—go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal …
CVE-2026-777637.140.7—JuiceFS Local Filestore Backend Joins Object Keys onto the Storage Root Without a Conta…
CVE-2026-923932.037.2—Apache YuniKorn: Admission control bypass via workload UPDATE operation
CVE-2026-637728.734.8—Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader…
CVE-2026-824588.734.8—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-836638.734.8—Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that …
CVE-2026-946378.234.8—Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame
CVE-2026-971464.828.3—Apache YuniKorn: Admission control bypass via system label forgery
CVE-2026-1025108.723.8—Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled …
CVE-2024-93556.520.6—Golang-fips: golang fips zeroed buffer
CVE-2026-660558.216.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-782432.115.1—Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
CVE-2026-977365.410.0——
CVE-2026-1025118.56.7—Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed r…

Most-affected packages

Packages with the most advisories
PackageCVEs
github.com/apache/thrift8
github.com/apache/yunikorn-k8shim3
github.com/apache/plc4x/plc4go2
github.com/golang-fips/openssl1
github.com/juicedata/juicefs1
github.com/tinyauthapp/tinyauth1