VulnSea

go has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.9 (medium). Most affected products: github.com/neuvector/neuvector (2), neuvector (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
4 prev 0

Products

  • github.com/neuvector/neuvector 2
  • neuvector 2
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

go vulnerabilities

CVEs affecting go, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-78428High· 8.0
5d ago

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

Twilightgo · neuvectorEPSS 0.24%via NVD
CVE-2026-78426Low· 3.7
5d ago

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…

Sunlitgo · neuvectorEPSS 0.12%via NVD
CVE-2026-78425High· 7.6
5d ago

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

Twilightgo · github.com/neuvector/neuvectorEPSS 0.35%via NVD
CVE-2026-78427Medium· 4.3
5d ago

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any…

Sunlitgo · github.com/neuvector/neuvectorEPSS 0.36%via NVD
go vulnerabilities (CVEs) · VulnSea