go has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.9 (medium). Most affected products: github.com/neuvector/neuvector (2), neuvector (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- github.com/neuvector/neuvector 2
- neuvector 2
Worst active — by depth score
CVE-2026-78428High· 8.0For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently44CVE-2026-78425High· 7.6Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…42CVE-2026-78427Medium· 4.3The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images24CVE-2026-78426Low· 3.7The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field20
go vulnerabilities
CVEs affecting go, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-78428High· 8.0For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
CVE-2026-78426Low· 3.7The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…
CVE-2026-78425High· 7.6Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…
Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…
CVE-2026-78427Medium· 4.3The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any…