boxscore/security
ECOSYSTEM · referenceEcosystems · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Go

Package ecosystem Go. A cumulative reference aggregating every published CVE with an advisory in this registry; not a page of record.

Totals
CVEs all-timeCVEs YTDPackages affected
432

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-559698.763.0Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-438718.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byt…
CVE-2026-485868.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2024-93556.522.4Golang-fips: golang fips zeroed buffer

Most-affected packages

Packages with the most advisories
PackageCVEs
github.com/apache/thrift3
github.com/golang-fips/openssl1