Go vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-43630Mediumgithub.com/lf-edge/eve: EVE Doesn't Measure Config Partition From 2 FrontsCVE-2025-62878Criticalgithub.com/rancher/local-path-provisioner: Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternCVE-2026-25538Highgithub.com/devtron-labs/devtron: Devtron Attributes API Unauthorized Access Leading to API Token Signing Key LeakageCVE-2026-25161Highgithub.com/alist-org/alist/v3: Alist vulnerable to Path Traversal in multiple file operation handlersCVE-2026-25160Criticalgithub.com/alist-org/alist/v3: Alist has Insecure TLS ConfigCVE-2026-24735Mediumgithub.com/apache/answer: Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerabilityCVE-2026-24514Mediumk8s.io/ingress-nginx: ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling CVE-2026-1580Highk8s.io/ingress-nginx: ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginxCVE-2026-24513Lowk8s.io/ingress-nginx: ingress-nginx has Improper Check for Unusual or Exceptional ConditionsCVE-2026-24512Highk8s.io/ingress-nginx: ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginxCVE-2026-25579Criticalgithub.com/navidrome/navidrome: Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>`…CVE-2026-25578Mediumgithub.com/navidrome/navidrome: Navidrome has XSS via comment from song metadataCVE-2026-25145Mediumchainguard.dev/melange: melange has a path traversal in license-path which allows reading files outside workspace CVE-2026-25143Highchainguard.dev/melange: melange affected by potential host command execution via license-check YAML mode patch pipeline CVE-2026-25140Highchainguard-dev/apko: apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streamsCVE-2026-25122Mediumchainguard.dev/apko: apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams CVE-2026-25121Highchainguard.dev/apko: apko has a path traversal in apko dirFS which allows filesystem writes outside baseCVE-2026-24844Highchainguard.dev/melange: melange pipeline working-directory could allow command injectionCVE-2026-24843Highchainguard.dev/melange: melange QEMU runner could write files outside workspace directoryCVE-2025-70849Lowgithub.com/stefanprodan/podinfo: Podinfo affected by Arbitrary File Upload that leads to Stored Cross-Site Scripting (XSS)CVE-2026-25518Mediumgithub.com/cert-manager/cert-manager: cert-manager-controller DoS via Specially Crafted DNS ResponseGHSA-GRH9-37G7-53MJMediumgithub.com/h44z/wg-portal: WireGuard Portal v2 has Open Redirect Vulnerability in OAuth Authentication FlowCVE-2026-25499Highgithub.com/bpg/terraform-provider-proxmox: terraform-provider-proxmox has insecure sudo recommendation in the documentationCVE-2026-25060Highgithub.com/OpenListTeam/OpenList/v4: OpenList has Insecure TLS Default ConfigurationCVE-2026-24051Highgo.opentelemetry.io/otel/sdk: OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

Stop the waste.
Protect your environment with Kodem.