IndexedVerified

Go Security

Go SAST rules aggregated across verified providers.

Fetch pack

greprules pack fetch go-security --engine opengrep
curl https://api.greprules.io/api/packs/go-security.tar.gz -o go-security.tar.gz

Included rules

328 rules included. Showing 24 loaded rules.
CVE-2026-55770: Improper Ldap Escape In Filtercve-2026-55770-improper-ldap-escape-in-filterCVE-2026-55185: Unbounded Html Tokenization No Early Exitcve-2026-55185-unbounded-html-tokenization-no-early-exitCVE-2026-54096: Filebrowser Improper Access Control Precreated Sharecve-2026-54096-filebrowser-improper-access-control-precreated-shareCVE-2026-54094: Afero Basepathfs Symlink Escapecve-2026-54094-afero-basepathfs-symlink-escapeCVE-2026-54091: Filebrowser Path Rebase Auth Bypasscve-2026-54091-filebrowser-path-rebase-auth-bypassCVE-2026-53475: Archive Chained Symlink Traversalcve-2026-53475-archive-chained-symlink-traversalCVE-2026-53471: Agentserver Server Go Cwe 000 Cve 2026 53471cve-2026-53471-agentserver-server-go-cwe-000-cve-2026-53471CVE-2026-52801: Gogs Mirror Address Ssrfcve-2026-52801-gogs-mirror-address-ssrfCVE-2026-52800: Csrf State Changing Get Routecve-2026-52800-csrf-state-changing-get-routeCVE-2026-50141: Grpc Metadata Auth Spoofingcve-2026-50141-grpc-metadata-auth-spoofingCVE-2026-50133: Hugo Missing Content Type Checkcve-2026-50133-hugo-missing-content-type-checkCVE-2026-49980: Rclone Unauthenticated Inline Remote Rcecve-2026-49980-rclone-unauthenticated-inline-remote-rceCVE-2026-48794: Case Sensitive Domain Matchcve-2026-48794-case-sensitive-domain-matchCVE-2026-48154: Env Path Traversal Mkdircve-2026-48154-env-path-traversal-mkdirCVE-2026-48089: Echo Unvalidated Path Param To Urlcve-2026-48089-echo-unvalidated-path-param-to-urlCVE-2026-48031: Go Chi Jwtauth Unvalidated Config Secretcve-2026-48031-go-chi-jwtauth-unvalidated-config-secretCVE-2026-47724: Stale Context Authz Checkcve-2026-47724-stale-context-authz-checkCVE-2026-47680: K8s Spec Filepath Join Traversalcve-2026-47680-k8s-spec-filepath-join-traversalCVE-2026-47125: Go Env File Write Without Key Regex Validationcve-2026-47125-go-env-file-write-without-key-regex-validationCVE-2026-47124: Nezha Missing Csrf Or Scope Validationcve-2026-47124-nezha-missing-csrf-or-scope-validationCVE-2026-46597: Integer Overflow Before Cast Bounds Checkcve-2026-46597-integer-overflow-before-cast-bounds-checkCVE-2026-46415: Caddy Middleware Unsafe Remoteaddrcve-2026-46415-caddy-middleware-unsafe-remoteaddrCVE-2026-46378: Unbounded Peek Loopcve-2026-46378-unbounded-peek-loopCVE-2026-46358: Inverted Redaction Logiccve-2026-46358-inverted-redaction-logic
24 of 328 loaded