IndexedVerified
Go Security
Go SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch go-security --engine opengrepcurl https://api.greprules.io/api/packs/go-security.tar.gz -o go-security.tar.gzIncluded rules
CVE-2026-84195: K8s Default Serviceaccount Token Read
cve-2026-84195-k8s-default-serviceaccount-token-readCVE-2026-82652: Siyuan Publish Access Missing Invisible Checkcve-2026-82652-siyuan-publish-access-missing-invisible-checkCVE-2026-82233: Mcp Tool Unvalidated Filepath Abscve-2026-82233-mcp-tool-unvalidated-filepath-absCVE-2026-81664: Openfaas Unprotected Telemetry Handlercve-2026-81664-openfaas-unprotected-telemetry-handlerCVE-2026-81521: Mongodb Bulkwrite Unvalidated Database Namespacecve-2026-81521-mongodb-bulkwrite-unvalidated-database-namespaceCVE-2026-81092: Mcp Missing Dns Rebinding Protectioncve-2026-81092-mcp-missing-dns-rebinding-protectionCVE-2026-81034: Go Tls Hardcoded Insecure Skip Verifycve-2026-81034-go-tls-hardcoded-insecure-skip-verifyCVE-2026-79780: Insecure Http Redirect Scheme Downgradecve-2026-79780-insecure-http-redirect-scheme-downgradeCVE-2026-79776: Go Unauthenticated Pprof Routecve-2026-79776-go-unauthenticated-pprof-routeCVE-2026-79775: Unhandled Squashfs Read Paniccve-2026-79775-unhandled-squashfs-read-panicCVE-2026-79668: Gin Unprotected Like Or Vote Endpointcve-2026-79668-gin-unprotected-like-or-vote-endpointCVE-2026-79667: Go Gin Query Token Context Bypasscve-2026-79667-go-gin-query-token-context-bypassCVE-2026-79664: Go Jwt Nil Expiresat Dereferencecve-2026-79664-go-jwt-nil-expiresat-dereferenceCVE-2026-79662: Go Oauth Redirect Insufficient Path Validationcve-2026-79662-go-oauth-redirect-insufficient-path-validationCVE-2026-79659: Go Ssrf Unvalidated Peer Urlcve-2026-79659-go-ssrf-unvalidated-peer-urlCVE-2026-79658: Unchecked Accept Language Parsecve-2026-79658-unchecked-accept-language-parseCVE-2026-77354: Kin Openapi Unvalidated Object Param Decodingcve-2026-77354-kin-openapi-unvalidated-object-param-decodingCVE-2026-76905: Kin Openapi Nil Parameter Dereferencecve-2026-76905-kin-openapi-nil-parameter-dereferenceCVE-2026-76216: Double Html Escaping Before Markdowncve-2026-76216-double-html-escaping-before-markdownCVE-2026-75926: Hugo Insecure Default Exec Allow Tailwindcsscve-2026-75926-hugo-insecure-default-exec-allow-tailwindcssCVE-2026-74796: Opentofu Registry Unauthenticated Direct Downloadcve-2026-74796-opentofu-registry-unauthenticated-direct-downloadCVE-2026-73611: Jwt Expiration Bypass Without Request Validationcve-2026-73611-jwt-expiration-bypass-without-request-validationCVE-2026-73610: Jwt Static Subject Claim In Account Loopcve-2026-73610-jwt-static-subject-claim-in-account-loopCVE-2026-73607: Go Jwt Hardcoded Subject Claimcve-2026-73607-go-jwt-hardcoded-subject-claim24 of 568 loaded