Go Project
First CVE: Nov 18, 2020Active for: 6 years
231
CVEs Published
More CVEs Published than 81% of tracked CNAs
38.5
Avg CVEs / Year
More Avg CVEs / Year than 81% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Go Project as a CNA, 2.6% affect products that Go Project develops as a vendor.
97.4%
Self-reported: 6Third-party: 225
Of all the CVEs published that affect products developed by Go Project, 100.0% are self-published by Go Project as a CNA.
100.0%
Self-published: 6Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Go Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2020
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Go Project as a CNA, regardless of affected vendor or product.
231 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45288HIGH An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing an | Apr 4, 2024 | 7.5 | 76 | NO | NO |
CVE-2026-39821CRITICAL The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns th | May 22, 2026 | 9.6 | 46 | NO | NO |
CVE-2026-46595CRITICAL Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-addre | May 22, 2026 | 10.0 | 44 | NO | NO |
CVE-2026-39830CRITICAL A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by | May 22, 2026 | 9.1 | 43 | NO | NO |
CVE-2026-42508CRITICAL Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked. | May 22, 2026 | 9.1 | 42 | NO | NO |
CVE-2026-39834CRITICAL When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, | May 22, 2026 | 9.1 | 42 | NO | NO |
CVE-2026-39832CRITICAL When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently st | May 22, 2026 | 9.1 | 42 | NO | NO |
CVE-2026-39831CRITICAL The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated with | May 22, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-39828HIGH When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restri | May 22, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-39833CRITICAL The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt | May 22, 2026 | 9.1 | 40 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA231 CVEs
33%
51%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local26 (11.3%)
Network204 (88.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low212 (91.8%)
High19 (8.2%)
Unknown0 (0.0%)
User Interaction
None194 (84.0%)
Unknown0 (0.0%)
Required37 (16.0%)
Privileges Required
Low24 (10.4%)
High2 (0.9%)
None205 (88.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (231 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Go Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Go Project as a CNA — matched by CVE ID, not by organization name.