Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-25804Highantrea.io/antrea: Antrea has invalid enforcement order for network policy rules caused by integer overflowGHSA-VHVQ-FV9F-WH4QLowgithub.com/authzed/spicedb: LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panicCVE-2026-25793Highgithub.com/slackhq/nebula: Blocklist Bypass possible via ECDSA Signature MalleabilityCVE-2025-65852Mediumgogs.io/gogs: Gogs has authorization bypass in repository deletion APIGHSA-26GQ-GRMH-6XM6Highgogs.io/gogs: Gogs vulnerable to Stored XSS via Mermaid diagramsCVE-2025-70963Mediumgithub.com/gophish/gophish: Gophish is vulnerable to Incorrect Access ControlCVE-2025-13523Highgithub.com/mattermost/mattermost-plugin-confluence: Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template renderingCVE-2026-24135Highgogs.io/gogs: Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page updateCVE-2026-23633Mediumgogs.io/gogs: Gogs has arbitrary file read/write via Path Traversal in Git hook editingCVE-2026-23632Mediumgogs.io/gogs: Gogs user can update repository content with read-only permissionCVE-2026-22592Mediumgogs.io/gogs: Gogs has a Denial of Service issueCVE-2025-64175Highgogs.io/gogs: Gogs Vulnerable to 2FA Bypass via Recovery CodeCVE-2025-64111Criticalgogs.io/gogs: Gogs's update .git/config file allows remote command executionCVE-2026-25760Mediumgithub.com/bishopfox/sliver: Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated)CVE-2026-24851Mediumgithub.com/openfga/openfga: OpenFGA Improper Policy EnforcementGHSA-VF5J-R2HW-2HRWHighgithub.com/opencloud-eu/opencloud: OpenCloud Affected by Public Link ExploitCVE-2026-23989Highgithub.com/opencloud-eu/reva/v2: OpenCloud Reva has a Public Link ExploitGHSA-X9P2-77V6-6VHFCriticalgithub.com/dunglas/frankenphp: FrankenPHP has delayed propagation of security fixes in upstream base imagesCVE-2023-43637Mediumgithub.com/lf-edge/eve: EVE Has Partially Predetermined Vault KeyCVE-2023-43636Mediumgithub.com/lf-edge/eve/pkg/grub: EVE Doesn't Protect RootfsCVE-2023-43635Mediumgithub.com/lf-edge/eve: EVE Seals Vault Key With SHA1 PCRsCVE-2023-43634Mediumgithub.com/lf-edge/eve: EVE Doesn't Protect Config Partition with Measured BootCVE-2023-43633Mediumgithub.com/lf-edge/eve: EVE's Debug Functions Unlockable Without Triggering Measured BootCVE-2023-43632Mediumgithub.com/lf-edge/eve: EVE Freely Allocates Buffer on The Stack With Data From SocketCVE-2023-43631Mediumgithub.com/lf-edge/eve: EVE: SSH as Root Unlockable Without Triggering Measured Boot

Stop the waste.
Protect your environment with Kodem.