Go
Vendor:
First CVE: Oct 7, 2014 · Active for 11 years
175
Total CVEs
More Total CVEs than 99% of tracked products
14.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Go over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2014
11 years ago
Most Recent CVE
Jul 8, 2026
18 days ago
CVE Severity & Scoring
Go175 CVEs
29%
58%
11%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (12.6%)
Network152 (86.9%)
Unknown1 (0.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low150 (85.7%)
High24 (13.7%)
Unknown1 (0.6%)
User Interaction
None147 (84.0%)
Unknown1 (0.6%)
Required27 (15.4%)
Privileges Required
Low14 (8.0%)
High1 (0.6%)
None159 (90.9%)
Unknown1 (0.6%)
Top CVEs
Signals from CVEs in this product scope (175 CVEs).
175 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2020-0601HIGH A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by u | Jan 14, 2020 | 8.1 | 97 | YES | YES |
CVE-2018-16873HIGH In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go packa | Dec 14, 2018 | 8.1 | 63 | NO | NO |
CVE-2018-7187HIGH The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string) | Feb 16, 2018 | 8.8 | 62 | NO | NO |
CVE-2025-68121CRITICAL During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed h | Feb 5, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-39822HIGH On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the pa | Jul 8, 2026 | 7.8 | 39 | NO | NO |
CVE-2026-33814HIGH When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. | May 7, 2026 | 7.5 | 39 | NO | NO |
CVE-2026-27143CRITICAL Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, p | Apr 8, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-42499HIGH Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | May 7, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-39820HIGH Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. | May 7, 2026 | 7.5 | 37 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (175 CVEs).
CISA KEV
2 CVEs
1.1% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (175 CVEs).
Media Mentions
Signals from CVEs in this product scope (175 CVEs).
Top CNAs Publishing CVEs For Go
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.3 | 1 | 7.8 | 7.6% | 0 | 0 |
| 1.9.2 | 1 | 7.8 | 7.6% | 0 | 0 |
| 1.9.1 | 1 | 7.8 | 7.6% | 0 | 0 |
| 1.9 | 3 | 7.8 | 5.9% | 0 | 0 |
| 1.8.1 | 1 | 5.9 | 2.2% | 0 | 0 |
| 1.8 | 1 | 5.9 | 2.2% | 0 | 0 |
| 1.7 | 1 | 8.1 | 5.2% | 0 | 0 |
| 1.6 | 2 | 7.7 | 2.4% | 0 | 0 |
| 1.5.2 | 1 | 7.5 | 2.6% | 0 | 0 |
| 1.5.1 | 1 | 7.5 | 2.6% | 0 | 0 |
| 1.5 | 1 | 7.5 | 2.6% | 0 | 0 |
| 1.3.1 | 1 | 4.3 | 1.4% | 0 | 0 |
| 1.3 | 1 | 4.3 | 1.4% | 0 | 0 |
| 1.27 | 2 | 6.5 | 0.2% | 0 | 0 |
| 1.26.0 | 6 | 7.1 | 0.5% | 0 | 0 |
| 1.2.2 | 1 | 4.3 | 1.4% | 0 | 0 |
| 1.21.0 | 1 | 5.3 | 1.3% | 0 | 0 |
| 1.2.1 | 1 | 4.3 | 1.4% | 0 | 0 |
| 1.20.0 | 4 | 7.5 | 1.6% | 0 | 0 |
| 1.2 | 1 | 4.3 | 1.4% | 0 | 0 |