Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Go Number Of NVD 138 CRITICAL 16 HIGH 83 MEDIUM 37 LOW 2
URL https://golang.org/
Explanation It is a programming language developed by Google.
It has a simple syntax and can be coded by anyone to look the same.
It has been adopted by many companies because it is good at parallel processing and can perform well on multi-core systems.
Since it is cross-compatible, it can be run in a variety of environments including Windows, Linux, Mac, and Android.

As a result of prioritizing simplicity, there are some disadvantages such as the lack of exception handling (there are alternative functions), which is common in other languages.
This may be implemented in the future.

A major release is made about every 6 months.
If a critical bug or security issue is fixed during the major release, a minor release is made.

The last two major releases are supported and covered.
Since major releases are made about every six months, the major version a year ago will no longer be supported.
Tag
  • BSD License
  • オープンソース

Add Information URL
No Type Name URL
1 https://github.com/golang/go/wiki/Go-Release-Cycle
2 https://golang.org/doc/devel/release.html
3 https://github.com/golang/go/wiki/MinorReleases
4 https://golang.org/security
5 https://golang.org/doc/copyright.html

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1 go 1.21 1.21.13 Aug. 6, 2024 June 16, 2023 2 14 12 1
2 go 1.20 1.20.7 Aug. 1, 2023 Feb. 1, 2023 6 22 14 1
3 go 1.19 1.19.13 Sept. 6, 2023 Aug. 2, 2022 6 29 15 1
4 Go 1.18 1.18.10 Jan. 10, 2023 March 15, 2022 6 41 19 2
5 Go 1.17 1.17.13 Aug. 1, 2022 Aug. 16, 2021 8 47 20 2
6 Go 1.16 1.16.15 March 3, 2022 Feb. 16, 2021 8 53 27 2
7 Go 1.15 1.15.15 Aug. 4, 2021 Aug. 11, 2020 8 58 29 2
8 Go 1.14 1.14.15 Feb. 4, 2021 Feb. 25, 2020 8 58 31 2
9 Go 1.13 1.13.15 Aug. 6, 2020 Sept. 3, 2019 8 62 31 2
10 Go 1.12 1.12.17 Feb. 12, 2020 Feb. 25, 2019 10 63 31 2
11 go 1.9 1.9.7 11 66 32 2
12 go 1.8 1.8.7 11 66 33 2
13 go 1.7 1.7.6 11 69 33 2
14 go 1.6 1.6.4 11 71 33 2
15 go 1.5 1.5.4 11 72 33 2
16 go 1.4 1.4.3 14 70 33 2
17 go 1.3 1.3.3 14 70 34 2
18 go 1.2 1.20.7 Aug. 1, 2023 14 71 35 2
19 go 1.12 1.12.9 10 63 31 2
20 go 1.11 1.11.9 10 63 32 2
21 go 1.10 1.10.8 10 66 31 2
22 go 1.1 1.19.13 Sept. 6, 2023 14 72 35 2
23 go 1.0 1.0.3 15 70 33 2
24 go 0.0 0.0.0-20201203163018-be400aefbc4c 14 69 33 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1 7.5
-
HIGH
Network
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module pr… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-42501 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 01:59
2026-05-8
Show GitHub Exploit DB Packet Storm
2 7.5
-
HIGH
Network
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. NVD-CWE-noinfo
CVE-2026-42499 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 01:59
2026-05-8
Show GitHub Exploit DB Packet Storm
3 7.5
-
HIGH
Network
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). CWE-476
 NULL Pointer Dereference
CVE-2026-39836 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 00:11
2026-05-8
Show GitHub Exploit DB Packet Storm
4 6.1
-
MEDIUM
Network
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape a… CWE-116
 Improper Encoding or Escaping of Output
CVE-2026-39826 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 01:59
2026-05-8
Show GitHub Exploit DB Packet Storm
5 5.3
-
MEDIUM
Network
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitize… NVD-CWE-noinfo
CVE-2026-39825 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 01:58
2026-05-8
Show GitHub Exploit DB Packet Storm
6 6.1
-
MEDIUM
Network
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune ins… CWE-79
Cross-site Scripting
CVE-2026-39823 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 01:58
2026-05-8
Show GitHub Exploit DB Packet Storm
7 7.5
-
HIGH
Network
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-39820 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 00:10
2026-05-8
Show GitHub Exploit DB Packet Storm
8 5.3
-
MEDIUM
Local
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one… CWE-59
Link Following
CVE-2026-39819 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-14 00:05
2026-05-8
Show GitHub Exploit DB Packet Storm
9 5.9
-
MEDIUM
Local
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" su… CWE-787
 Out-of-bounds Write
CVE-2026-39817 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-13 23:59
2026-05-8
Show GitHub Exploit DB Packet Storm
10 7.5
-
HIGH
Network
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-33814 cpe:2.3:a:golang:go:*:*
1.26.0


1.25.10
1.26.3
2026-05-13 23:41
2026-05-8
Show GitHub Exploit DB Packet Storm