AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58507

MEDIUM · CVSS 5.3 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows unauthorized users to discover the existence of private repositories through the go-get meta endpoint, potentially exposing sensitive project information. Organizations utilizing Go modules for private repositories should prioritize addressing this issue to prevent unintended information disclosure. Immediate action is recommended for teams managing proprietary codebases to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58507
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%

Original NVD Description

Private Repository Existence Disclosure via go-get Meta Endpoint