Go Project

First CVE: Nov 18, 2020Active for: 6 years
231
CVEs Published
More CVEs Published than 81% of tracked CNAs
38.5
Avg CVEs / Year
More Avg CVEs / Year than 81% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Go Project as a CNA, 2.6% affect products that Go Project develops as a vendor.

97.4%
Self-reported: 6Third-party: 225

Of all the CVEs published that affect products developed by Go Project, 100.0% are self-published by Go Project as a CNA.

100.0%
Self-published: 6Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Go Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2020
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Go Project as a CNA, regardless of affected vendor or product.

231 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing an
Apr 4, 20247.576NONO
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns th
May 22, 20269.646NONO
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-addre
May 22, 202610.044NONO
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by
May 22, 20269.143NONO
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
May 22, 20269.142NONO
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely,
May 22, 20269.142NONO
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently st
May 22, 20269.142NONO
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated with
May 22, 20269.141NONO
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restri
May 22, 20268.841NONO
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt
May 22, 20269.140NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA231 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local26 (11.3%)
Network204 (88.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low212 (91.8%)
High19 (8.2%)
Unknown0 (0.0%)
User Interaction
None194 (84.0%)
Unknown0 (0.0%)
Required37 (16.0%)
Privileges Required
Low24 (10.4%)
High2 (0.9%)
None205 (88.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (231 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Go Project as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Go Project as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs